They thought they were downloading Claude Code source. They got a nasty dose of malware instead

2026-04-02T19:23:56Z67f9030ea748090de705f29b025dc836cbf6f7b7fbee51cb79a4d819e083c41c
GhostSocksVidarai-model-leakcredential-stealerdeveloper-targetinggithubmalwaresupply-chaintoken-exfiltrationtrojanized-source

What happened

Attackers distributed trojanized copies of the leaked Claude Code source that bundled credential‑stealing malware (reported as Vidar) and a GhostSocks backdoor/proxy. Tens of thousands of users downloaded the poisoned packages from popular developer distribution channels, putting developer machines, API keys, tokens, and downstream supply chains at risk of credential theft and remote access. Organisations and devs should assume compromise, rotate keys, scan and rebuild affected hosts from clean images, and only use verified official sources/releases.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
67f9030ea748090de705f29b025dc836cbf6f7b7fbee51cb79a4d819e083c41c
Enrichment time
2026-04-02T19:23:56Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.