Claude Code Leak Exploited: Fake GitHub Repos Push Infostealers

Claude Code Leak Exploited: Fake GitHub Repos Push Infostealers

The recent leak of Claude Code has rapidly become a lure for malicious actors. Threat actors are capitalizing on the attention surrounding the leaked code by creating fake repositories on GitHub. These impostor repositories masquerade as ‘open-source’ or ‘upgraded’ versions of Claude Code, but their true purpose is to distribute malware, specifically the Vidar infostealer.

Users searching for ‘leaked Claude Code’ might encounter these deceptive repositories high in search results. Downloading and executing a file like ‘ClaudeCode_x64.exe’ from such a source can lead to the deployment of Vidar and GhostSocks. These tools are designed to steal sensitive information and exfiltrate traffic, often through proxying. Security researchers at Zscaler have linked this activity to repositories published by a user identified as ‘idbzoomh’.

This incident serves as a critical reminder that not every code leak, especially those found on platforms like GitHub, is a valuable resource. Sometimes, what appears to be a legitimate release is merely a Trojan horse, hiding malicious payloads beneath a veneer of open-source accessibility. Vigilance is paramount when engaging with leaked or unverified code.

What This Means For You

  • Data exposure reported — check if your organization or users are affected.
  • New tool or resource available — evaluate for your security workflow.
🔎
Is your vendor affected? Start hunting now. Search by organization or domain, set watchlist alerts, and get notified when your third parties are compromised.
Open Intel Bot →

Related coverage

Grafana Breach: Missed Token Rotation After TanStack Supply Chain Attack

BleepingComputer reports that the recent Grafana data breach stemmed from a single GitHub workflow token that was not rotated following the TanStack npm supply-chain attack....

threat-inteldata-breachmalwaretools
/SCW Research /MEDIUM /⚙ 3 Sigma

Drupal Critical Update: Exploitation Risk Hours After Disclosure

Drupal has issued a critical security advisory, urging users to apply a core security update immediately. BleepingComputer reports that the vendor anticipates threat actors will...

threat-inteldata-breachmalwarevulnerabilitytools
/SCW Vulnerability Desk /MEDIUM /⚑ 2 IOCs /⚙ 3 Sigma

GitHub Confirms Breach by TeamPCP, Customer Data Unaffected

GitHub confirmed a breach by the threat actor TeamPCP, following TeamPCP's advertisement of stolen source code on a cybercrime forum. According to The Record by...

threat-inteldata-breachgovernmenttools
/SCW Research /MEDIUM /⚙ 3 Sigma