Alert Across the Internet! Claude Code Source Code Leak Triggers "Secondary Disaster": Hackers Set GitHub Phishing Traps

marsbitPublished on 2026-04-03Last updated on 2026-04-03

Abstract

A major security alert is circulating online following the accidental leak of Claude Code's source code by Anthropic. Hackers are exploiting the incident by creating fake GitHub repositories that distribute the information-stealing malware known as **Vidar**. Posing as a user named `idbzoomh`, the threat actor set up multiple repositories claiming to offer "unlocked enterprise features" from the leaked source code. These repositories are optimized for search engines to appear at the top of results for queries like “Claude Code leak,” increasing their reach. If a user downloads and executes the provided files, the Vidar malware is deployed. It is a sophisticated stealer designed to harvest sensitive data such as browser credentials, cryptocurrency wallets, and personal information. The attack also installs **GhostSocks**, a proxy tool that establishes hidden communication channels for remote control and data exfiltration. Security firm Zscaler notes that these malicious repositories update frequently, making it easier to bypass basic security scans. At least two similar repositories have been identified, suggesting the same attacker is testing different distribution methods. This incident highlights the compound risks in the AI era, where initial human error leads to secondary threats like social engineering. Developers are urged to obtain software only through official channels and avoid executing untrusted binaries.

According to an April 2nd report, the Claude Code source code leak incident caused by an Anthropic human error continues to escalate. Currently, hackers have exploited this hot topic to spread information-stealing malware named Vidar via fake repositories on GitHub.

Upgraded Bait: Claiming to "Unlock Enterprise-Level Features"

Monitoring reports from security company Zscaler show that a user named idbzoomh has created multiple fake repositories on GitHub.

  • Precision Phishing: The hacker claims in the repository description to provide leaked source code that "unlocks enterprise features," luring eager developers to download it.

  • SEO Optimization: To maximize the impact, the attackers optimized for search engine keywords, causing these malicious repositories to often rank at the top when users search for terms like "Claude Code leak".

Virus Profile: Vidar Infiltrates, Data "Relocated"

Once users are deceived into downloading and executing the contained executable files, the system is quickly compromised:

  • Information Theft: The implanted Vidar is a highly mature malware on the dark web, specifically designed to harvest browser account passwords, cryptocurrency wallets, and various types of sensitive personal information.

  • Persistent Latency: The virus also simultaneously deploys the GhostSocks proxy tool, setting up a secret channel for subsequent remote control and data exfiltration.

Risk Warning: Beware of "Free Lunches" from Unofficial Channels

Security researchers point out that the malicious compressed files in these fake repositories are updated at an extremely high frequency, making them easy to bypass basic security detection. At least two repositories with similar tactics have been discovered so far, suspected to be tests of different propagation strategies by the same attacker.

Industry Observation: The "Chain Set" of AI Security

From Anthropic's source code packaging mistake to hackers secondarily exploiting the hot topic for phishing, this incident reflects the complexity of security risks in the AI era. When the developer community becomes the target of attacks, basic digital literacy—not running binaries from unknown sources—remains the last line of defense.

Editors remind all developers: Please be sure to obtain tools through official Anthropic channels. Do not fall into the traps carefully designed by hackers out of curiosity or the pursuit of "cracked features."

Related Questions

QWhat is the primary malware being distributed through the fake GitHub repositories related to the Claude Code leak?

AThe primary malware being distributed is called Vidar, which is a sophisticated information-stealing malware known for harvesting browser credentials, cryptocurrency wallets, and other sensitive personal data.

QHow are the attackers making their fake GitHub repositories more visible to potential victims?

AThe attackers are using Search Engine Optimization (SEO) techniques by including popular keywords like 'Claude Code leak' in the repository descriptions, causing these malicious repositories to appear at the top of search results.

QWhat additional tool does the Vidar malware deploy on an infected system to maintain persistence and enable data exfiltration?

AThe Vidar malware also deploys a tool called GhostSocks, which is a proxy utility that creates a secret channel for remote control and ongoing data exfiltration from the compromised system.

QWhat human error at Anthropic initially led to the situation that hackers are exploiting?

AThe initial event was a source code leak of Claude Code caused by a human error at Anthropic, where the code was mistakenly made available, creating the opportunity for hackers to use it as a lure.

QWhat is the main advice from security researchers to developers to avoid falling victim to these traps?

AThe main advice is to only obtain tools through official Anthropic channels and to avoid downloading or running binary files from unverified sources, emphasizing that basic digital hygiene is the last line of defense.

Related Reads

Brale Claims New Protocol Can Eliminate a Major Obstacle to Scaling Custom Tokens

Stablecoin infrastructure firm Brale is launching a compatibility protocol, called ION, designed to solve a key bottleneck in the industry: moving the rapidly growing number of custom-branded stablecoins across different blockchains. The protocol allows participating stablecoins to move between blockchains by burning tokens on one network and minting an equivalent amount on another. Unlike most blockchain bridges, this model does not require pre-funded liquidity pools in each supported chain. While the $300 billion stablecoin market is dominated by Tether (USDT) and Circle’s USDC, a wave of new entrants—including banks, fintechs, crypto firms, and asset managers—are issuing their own tokens for payments, settlements, and tokenized assets. Over 350 such asset-pegged coins are already tracked, highlighting the need for infrastructure to connect this increasingly fragmented ecosystem. Brale, which supports over 100 stablecoin programs across more than 30 blockchains, argues that current interoperability models relying on liquidity pools or wrapped tokens are not scalable. These models require locking up capital in every supported network, creating an unsustainable capital requirement as the number of stablecoins and blockchains grows. Brale's founder and CEO, Ben Miln, stated that "liquidity between stablecoin programs is the No. 1 barrier to scaling individual stablecoins," noting there isn't enough capital in the world to solve the problem via liquidity pools. ION's burn-and-mint approach, similar to Circle's Cross-Chain Transfer Protocol (CCTP) but extended to any participating issuer, aims to provide a scalable alternative. The protocol will debut initially on testnet with partners including Monad, Rain, Coinflow, Turnkey, Etherfuse, Spark, and Canton.

cryptonews.ru10m ago

Brale Claims New Protocol Can Eliminate a Major Obstacle to Scaling Custom Tokens

cryptonews.ru10m ago

Ethereum Foundation adds pcaversaccio to its board

The Ethereum Foundation (EF) has appointed long-time ecosystem contributor pcaversaccio (pc) to its board of directors, further refining the governance of the organization behind the world's second-largest blockchain. A security researcher and co-founder of the SEAL 911 emergency response initiative, pcaversaccio joins the board for an initial voluntary one-year term. He has previously served on the EF's Silviculture Society, an advisory group providing informal guidance on upholding the foundation's core principles, including censorship resistance, open-source development, privacy, and security. With this appointment, the EF board now consists of four members: President Aya Miyaguchi, Ethereum co-founder Vitalik Buterin, Swiss legal counsel Patrick Storchenegger, and pcaversaccio. The board is responsible for setting the EF's strategic vision, ensuring leadership decisions align with its values, and acting as a "security council" to safeguard the foundation's mission and ensure compliance with Swiss law, where it is based. This move comes during a period of significant change for the Ethereum Foundation. In recent months, several senior researchers and executives have departed, with some launching new Ethereum-focused ventures outside the foundation. The EF is shifting its role toward long-term stewardship rather than acting as the central hub for ecosystem development. The foundation expressed its enthusiasm for pcaversaccio's appointment, stating it looks forward to collaborating to help steward Ethereum's long-term future.

cryptonews.ru11m ago

Ethereum Foundation adds pcaversaccio to its board

cryptonews.ru11m ago

Trading

Spot
活动图片