Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning

2026-05-22T14:52:16Zd93feb93f91a8db3bd7131a6a16fbe4d82215884fcf81c9af4764e24dc106faa
agentic-aiai-securityandroid-malwareavada-builderexchange-zero-dayfragnesiagithub-breachgrafanagremlin-stealerinfostealerlinux-kernel-flawmalicious-extensionnpm-compromisepremium-fraudptraceransomware-enablerssbomseo-poisoningsource-code-theftsupply-chaintanstackvpn-takedownvs-code-extensionwordpress

What happened

Multiple high-impact supply‑chain incidents, active malware campaigns and critical vulnerabilities were reported. SEO‑poisoning campaigns used fake Gemini/Claude code sites to distribute infostealers that harvest credentials, crypto wallets and authentication keys; modular Gremlin stealer and a large Android premium‑billing fraud campaign remain active. Significant supply‑chain compromises and code theft include a malicious 'Nx Console' VS Code extension tied to a GitHub breach and stolen source code (Grafana/TanStack), Mini Shai‑Hulud infections across TanStack npm packages and PyPI, and Avda

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
d93feb93f91a8db3bd7131a6a16fbe4d82215884fcf81c9af4764e24dc106faa
Enrichment time
2026-05-22T14:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning · Baitaphish