Alert Across the Internet! Claude Code Source Code Leak Triggers "Secondary Disaster": Hackers Set GitHub Phishing Traps

marsbit2026-04-03 tarihinde yayınlandı2026-04-03 tarihinde güncellendi

Özet

A major security alert is circulating online following the accidental leak of Claude Code's source code by Anthropic. Hackers are exploiting the incident by creating fake GitHub repositories that distribute the information-stealing malware known as **Vidar**. Posing as a user named `idbzoomh`, the threat actor set up multiple repositories claiming to offer "unlocked enterprise features" from the leaked source code. These repositories are optimized for search engines to appear at the top of results for queries like “Claude Code leak,” increasing their reach. If a user downloads and executes the provided files, the Vidar malware is deployed. It is a sophisticated stealer designed to harvest sensitive data such as browser credentials, cryptocurrency wallets, and personal information. The attack also installs **GhostSocks**, a proxy tool that establishes hidden communication channels for remote control and data exfiltration. Security firm Zscaler notes that these malicious repositories update frequently, making it easier to bypass basic security scans. At least two similar repositories have been identified, suggesting the same attacker is testing different distribution methods. This incident highlights the compound risks in the AI era, where initial human error leads to secondary threats like social engineering. Developers are urged to obtain software only through official channels and avoid executing untrusted binaries.

According to an April 2nd report, the Claude Code source code leak incident caused by an Anthropic human error continues to escalate. Currently, hackers have exploited this hot topic to spread information-stealing malware named Vidar via fake repositories on GitHub.

Upgraded Bait: Claiming to "Unlock Enterprise-Level Features"

Monitoring reports from security company Zscaler show that a user named idbzoomh has created multiple fake repositories on GitHub.

  • Precision Phishing: The hacker claims in the repository description to provide leaked source code that "unlocks enterprise features," luring eager developers to download it.

  • SEO Optimization: To maximize the impact, the attackers optimized for search engine keywords, causing these malicious repositories to often rank at the top when users search for terms like "Claude Code leak".

Virus Profile: Vidar Infiltrates, Data "Relocated"

Once users are deceived into downloading and executing the contained executable files, the system is quickly compromised:

  • Information Theft: The implanted Vidar is a highly mature malware on the dark web, specifically designed to harvest browser account passwords, cryptocurrency wallets, and various types of sensitive personal information.

  • Persistent Latency: The virus also simultaneously deploys the GhostSocks proxy tool, setting up a secret channel for subsequent remote control and data exfiltration.

Risk Warning: Beware of "Free Lunches" from Unofficial Channels

Security researchers point out that the malicious compressed files in these fake repositories are updated at an extremely high frequency, making them easy to bypass basic security detection. At least two repositories with similar tactics have been discovered so far, suspected to be tests of different propagation strategies by the same attacker.

Industry Observation: The "Chain Set" of AI Security

From Anthropic's source code packaging mistake to hackers secondarily exploiting the hot topic for phishing, this incident reflects the complexity of security risks in the AI era. When the developer community becomes the target of attacks, basic digital literacy—not running binaries from unknown sources—remains the last line of defense.

Editors remind all developers: Please be sure to obtain tools through official Anthropic channels. Do not fall into the traps carefully designed by hackers out of curiosity or the pursuit of "cracked features."

İlgili Sorular

QWhat is the primary malware being distributed through the fake GitHub repositories related to the Claude Code leak?

AThe primary malware being distributed is called Vidar, which is a sophisticated information-stealing malware known for harvesting browser credentials, cryptocurrency wallets, and other sensitive personal data.

QHow are the attackers making their fake GitHub repositories more visible to potential victims?

AThe attackers are using Search Engine Optimization (SEO) techniques by including popular keywords like 'Claude Code leak' in the repository descriptions, causing these malicious repositories to appear at the top of search results.

QWhat additional tool does the Vidar malware deploy on an infected system to maintain persistence and enable data exfiltration?

AThe Vidar malware also deploys a tool called GhostSocks, which is a proxy utility that creates a secret channel for remote control and ongoing data exfiltration from the compromised system.

QWhat human error at Anthropic initially led to the situation that hackers are exploiting?

AThe initial event was a source code leak of Claude Code caused by a human error at Anthropic, where the code was mistakenly made available, creating the opportunity for hackers to use it as a lure.

QWhat is the main advice from security researchers to developers to avoid falling victim to these traps?

AThe main advice is to only obtain tools through official Anthropic channels and to avoid downloading or running binary files from unverified sources, emphasizing that basic digital hygiene is the last line of defense.

İlgili Okumalar

Qualcomm and Arm Fall Together: The Bill for Memory Price Hikes Finally Arrives at Mobile Chip Companies

After posting Q2 FY2026 results, Qualcomm and Arm both saw their shares decline, reflecting the impact of memory price increases on the smartphone chip sector. Qualcomm's revenue of $9.95B slightly beat expectations, but EPS of $2.21 fell short. More concerning was its guidance for next quarter, with EPS projections below analyst estimates. The company directly attributed a >$1.50 per share annual EPS headwind to rising memory costs and supply constraints in Android phones, prompting planned price hikes. While automotive revenue grew 61% and is approaching one-third of phone revenue, the mobile segment declined 20%. Qualcomm also confirmed a significant reduction in its modem share for the upcoming iPhone and outlined a plan for data center revenue to replace all Apple-related income by FY2027. Arm's results surpassed expectations with revenue of $1.29B and EPS of $0.45, and its guidance was also strong. However, its stock fell. Key concerns included royalty revenue failing to set a new record and a downward revision to full-year royalty growth guidance from ~20% to the high-teens, citing weak smartphone demand and high memory prices. Despite robust growth in its data center business, Arm's premium valuation (over 100x forward P/E) means even beating expectations isn't enough to push the stock higher, as any sign of uncertainty is magnified. Ongoing global antitrust investigations add another risk factor. The situation highlights a broader shift. Memory price surges, which boosted Samsung's profits, are now pressuring chip designers. Meanwhile, the semiconductor sector saw significant corrections in July, with the hardest-hit stocks often being those with the biggest AI-driven gains year-to-date. Qualcomm, lacking such a premium, was an exception.

marsbit4 dk önce

Qualcomm and Arm Fall Together: The Bill for Memory Price Hikes Finally Arrives at Mobile Chip Companies

marsbit4 dk önce

13 Business Lines Surpass $100 Million in Annualized Revenue, Robinhood Moves Toward a 'Super Financial App'

Robinhood Q2 2026 Earnings: Record Revenue and a Push Towards a "Super Financial App" Robinhood (HOOD) reported strong Q2 2026 results, with net revenue reaching $1.308 billion, up 32% year-over-year, and net income hitting $561 million, a 45% increase. The company now has 13 distinct business lines each generating over $100 million in annualized revenue. Key drivers included a 44% surge in transaction-based revenue to $776 million, led by a more than 10x growth in "event contracts" (prediction markets) and strong performance in stocks and options. User metrics also grew, with funded accounts rising to 28.4 million and total assets under custody reaching $369 billion. The Robinhood Gold subscription service hit a record 4.8 million users. The report highlights a strategic shift for Robinhood. Moving beyond its core as a zero-commission trading platform for retail investors, it is actively building a broader financial ecosystem. This includes expanding into wealth management (Robinhood Strategies), payments (Robinhood Credit Card), and next-generation infrastructure like AI-powered "Agentic Trading" and its own Ethereum Layer 2 blockchain, Robinhood Chain. The company's goal is to evolve from a trading app into a comprehensive "super financial app," offering a one-stop shop for investing, cash management, and future on-chain finance.

Odaily星球日报34 dk önce

13 Business Lines Surpass $100 Million in Annualized Revenue, Robinhood Moves Toward a 'Super Financial App'

Odaily星球日报34 dk önce

13 Business Lines Surpass $100 Million in Annualized Revenue, Robinhood Advances Toward a 'Super Financial App'

On July 30th, Robinhood (HOOD) reported its Q2 2026 financial results, showcasing significant growth with record revenue and profits. The company achieved a net revenue of $1.308 billion, a 32% year-over-year (YoY) increase, and a net income of $561 million, up 45% YoY. This strong performance was driven by robust trading activity and expansion into new financial services. A key highlight was the surge in transaction-based revenue, which rose 44% YoY to $776 million. Notably, income from event contracts (prediction markets) skyrocketed over 10x to $156 million, emerging as a major new growth driver alongside strong gains in stock and options trading. However, crypto trading revenue declined by 38%. Beyond trading, Robinhood is successfully diversifying its revenue streams. User assets grew 32% to $369 billion, and the subscription service Robinhood Gold reached a record 4.8 million users. The company revealed that 13 of its business lines now generate over $100 million in annualized revenue, including its new credit card, prediction markets, and Gold subscriptions. Looking forward, Robinhood is strategically investing in AI and blockchain to build a comprehensive financial ecosystem. It has launched AI-powered "Agentic Trading" and the "Robinhood Chain," a layer-2 blockchain network. The company's vision is evolving from a retail trading platform into a "super financial app" that integrates trading, wealth management, payments, and next-generation digital asset services, though regulatory hurdles remain for some new ventures.

marsbit34 dk önce

13 Business Lines Surpass $100 Million in Annualized Revenue, Robinhood Advances Toward a 'Super Financial App'

marsbit34 dk önce

İşlemler

Spot
活动图片