Alert Across the Internet! Claude Code Source Code Leak Triggers "Secondary Disaster": Hackers Set GitHub Phishing Traps

marsbitPublicado em 2026-04-03Última atualização em 2026-04-03

Resumo

A major security alert is circulating online following the accidental leak of Claude Code's source code by Anthropic. Hackers are exploiting the incident by creating fake GitHub repositories that distribute the information-stealing malware known as **Vidar**. Posing as a user named `idbzoomh`, the threat actor set up multiple repositories claiming to offer "unlocked enterprise features" from the leaked source code. These repositories are optimized for search engines to appear at the top of results for queries like “Claude Code leak,” increasing their reach. If a user downloads and executes the provided files, the Vidar malware is deployed. It is a sophisticated stealer designed to harvest sensitive data such as browser credentials, cryptocurrency wallets, and personal information. The attack also installs **GhostSocks**, a proxy tool that establishes hidden communication channels for remote control and data exfiltration. Security firm Zscaler notes that these malicious repositories update frequently, making it easier to bypass basic security scans. At least two similar repositories have been identified, suggesting the same attacker is testing different distribution methods. This incident highlights the compound risks in the AI era, where initial human error leads to secondary threats like social engineering. Developers are urged to obtain software only through official channels and avoid executing untrusted binaries.

According to an April 2nd report, the Claude Code source code leak incident caused by an Anthropic human error continues to escalate. Currently, hackers have exploited this hot topic to spread information-stealing malware named Vidar via fake repositories on GitHub.

Upgraded Bait: Claiming to "Unlock Enterprise-Level Features"

Monitoring reports from security company Zscaler show that a user named idbzoomh has created multiple fake repositories on GitHub.

  • Precision Phishing: The hacker claims in the repository description to provide leaked source code that "unlocks enterprise features," luring eager developers to download it.

  • SEO Optimization: To maximize the impact, the attackers optimized for search engine keywords, causing these malicious repositories to often rank at the top when users search for terms like "Claude Code leak".

Virus Profile: Vidar Infiltrates, Data "Relocated"

Once users are deceived into downloading and executing the contained executable files, the system is quickly compromised:

  • Information Theft: The implanted Vidar is a highly mature malware on the dark web, specifically designed to harvest browser account passwords, cryptocurrency wallets, and various types of sensitive personal information.

  • Persistent Latency: The virus also simultaneously deploys the GhostSocks proxy tool, setting up a secret channel for subsequent remote control and data exfiltration.

Risk Warning: Beware of "Free Lunches" from Unofficial Channels

Security researchers point out that the malicious compressed files in these fake repositories are updated at an extremely high frequency, making them easy to bypass basic security detection. At least two repositories with similar tactics have been discovered so far, suspected to be tests of different propagation strategies by the same attacker.

Industry Observation: The "Chain Set" of AI Security

From Anthropic's source code packaging mistake to hackers secondarily exploiting the hot topic for phishing, this incident reflects the complexity of security risks in the AI era. When the developer community becomes the target of attacks, basic digital literacy—not running binaries from unknown sources—remains the last line of defense.

Editors remind all developers: Please be sure to obtain tools through official Anthropic channels. Do not fall into the traps carefully designed by hackers out of curiosity or the pursuit of "cracked features."

Perguntas relacionadas

QWhat is the primary malware being distributed through the fake GitHub repositories related to the Claude Code leak?

AThe primary malware being distributed is called Vidar, which is a sophisticated information-stealing malware known for harvesting browser credentials, cryptocurrency wallets, and other sensitive personal data.

QHow are the attackers making their fake GitHub repositories more visible to potential victims?

AThe attackers are using Search Engine Optimization (SEO) techniques by including popular keywords like 'Claude Code leak' in the repository descriptions, causing these malicious repositories to appear at the top of search results.

QWhat additional tool does the Vidar malware deploy on an infected system to maintain persistence and enable data exfiltration?

AThe Vidar malware also deploys a tool called GhostSocks, which is a proxy utility that creates a secret channel for remote control and ongoing data exfiltration from the compromised system.

QWhat human error at Anthropic initially led to the situation that hackers are exploiting?

AThe initial event was a source code leak of Claude Code caused by a human error at Anthropic, where the code was mistakenly made available, creating the opportunity for hackers to use it as a lure.

QWhat is the main advice from security researchers to developers to avoid falling victim to these traps?

AThe main advice is to only obtain tools through official Anthropic channels and to avoid downloading or running binary files from unverified sources, emphasizing that basic digital hygiene is the last line of defense.

Leituras Relacionadas

Cyclical Stock or Growth Stock? Coinbase's Q2 Earnings Report Reveals 'Valuation Disagreement'

Coinbase's Q2 2026 financial results revealed a mixed performance, reigniting debate over whether the company should be valued as a cyclical stock tied to crypto markets or a growth stock with future potential. Total revenue missed expectations at $1.22 billion, down 19% year-over-year. Transaction revenue fell to $599 million, with retail crypto spot trading revenue dropping 30% to $452 million, back to 2023 levels. The company reported a net loss of $359 million, marking its third consecutive quarterly loss. Despite CEO Brian Armstrong's positive commentary on metrics like a 10.3% overall crypto trading market share and 106% growth in prediction markets, the market reacted negatively, with shares dropping over 5% after-hours. A key issue is the decline in core retail trading. While Coinbase touted record market share, this figure includes derivatives and new products. Its traditional crypto spot trading share is likely shrinking. New ventures like prediction markets, while growing, contributed less than $30 million, insufficient to offset the core revenue decline. The valuation debate hinges on perspective. As a cyclical stock, Coinbase remains deeply tied to the crypto bear market, with user attrition and competitive pressures justifying a lower valuation. The company's strategy appears focused on surviving until the next bull cycle. Viewed as a growth stock, however, Coinbase shows promising diversification. Subscription and service revenue reached $555 million, nearly matching transaction revenue. Stablecoin revenue, its second-largest source at $292 million, remains strong through its partnership with Circle. Critically, Coinbase is positioning itself as a leader in the emerging on-chain "agent economy." Over 90% of agent-based stablecoin transactions occur on its Base network, which it believes could handle trillions in future agent transactions. The recent acquisition of Deribit also aims to boost its international derivatives offering. In summary, Coinbase's present struggles are clear, but its future hinges on whether its investments in revenue diversification, stablecoins, and the agent economy can ultimately transform its business model and justify a growth premium.

Odaily星球日报Há 6m

Cyclical Stock or Growth Stock? Coinbase's Q2 Earnings Report Reveals 'Valuation Disagreement'

Odaily星球日报Há 6m

Global Market Share Survey: Japanese Firms Lead in Semiconductor Materials

Global Market Share Survey: Japanese Firms Lead in Semiconductor Materials According to the 2025 "Major Goods and Services Market Share Survey" by Nikkei, Japanese companies maintain strong positions in semiconductor-related materials. In silicon wafers, Shin-Etsu Chemical ranks first with a 26.3% share, followed by SUMCO at 17.8%. Together, they hold 44.1% of the market, widening their lead over competitors from Taiwan, Germany, and South Korea. In photoresists, Tokyo Ohka Kogyo, JSR, and Shin-Etsu Chemical occupy the top three spots, with a combined share of 60.5%. Despite their strength in materials, Japanese firms have a weaker presence in core semiconductor segments like DRAM and NAND flash memory, where South Korean and U.S. companies dominate. For instance, SK Hynix and Samsung lead in DRAM, while China’s CXMT doubled its share to 6% in 2025. The semiconductor market is projected to grow rapidly, with WSTS forecasting a 90% increase to $1.5112 trillion by 2026. Major players like Samsung, SK Hynix, and Micron are making massive investments to expand capacity. To maintain their edge in materials, Japanese companies must similarly commit to large-scale, risk-taking investments. In contrast, Japan’s automotive sector shows stagnation. Toyota remains the global leader but with only a slight share increase to 12.3%, while Japanese brands are absent from the top five in the EV market. In shipbuilding, Imabari Shipbuilding rose to third place globally with a 7.2% share, benefiting from large container ship deliveries. However, Chinese and South Korean firms dominate the sector, holding the top two positions. Japan aims to revitalize its shipbuilding industry through government and corporate efforts, targeting a near doubling of output by 2035. Addressing labor shortages and adopting advanced technologies like physical AI will be critical for competitiveness.

marsbitHá 31m

Global Market Share Survey: Japanese Firms Lead in Semiconductor Materials

marsbitHá 31m

Trading

Spot
活动图片