Alert Across the Internet! Claude Code Source Code Leak Triggers "Secondary Disaster": Hackers Set GitHub Phishing Traps

marsbitОпубліковано о 2026-04-03Востаннє оновлено о 2026-04-03

Анотація

A major security alert is circulating online following the accidental leak of Claude Code's source code by Anthropic. Hackers are exploiting the incident by creating fake GitHub repositories that distribute the information-stealing malware known as **Vidar**. Posing as a user named `idbzoomh`, the threat actor set up multiple repositories claiming to offer "unlocked enterprise features" from the leaked source code. These repositories are optimized for search engines to appear at the top of results for queries like “Claude Code leak,” increasing their reach. If a user downloads and executes the provided files, the Vidar malware is deployed. It is a sophisticated stealer designed to harvest sensitive data such as browser credentials, cryptocurrency wallets, and personal information. The attack also installs **GhostSocks**, a proxy tool that establishes hidden communication channels for remote control and data exfiltration. Security firm Zscaler notes that these malicious repositories update frequently, making it easier to bypass basic security scans. At least two similar repositories have been identified, suggesting the same attacker is testing different distribution methods. This incident highlights the compound risks in the AI era, where initial human error leads to secondary threats like social engineering. Developers are urged to obtain software only through official channels and avoid executing untrusted binaries.

According to an April 2nd report, the Claude Code source code leak incident caused by an Anthropic human error continues to escalate. Currently, hackers have exploited this hot topic to spread information-stealing malware named Vidar via fake repositories on GitHub.

Upgraded Bait: Claiming to "Unlock Enterprise-Level Features"

Monitoring reports from security company Zscaler show that a user named idbzoomh has created multiple fake repositories on GitHub.

  • Precision Phishing: The hacker claims in the repository description to provide leaked source code that "unlocks enterprise features," luring eager developers to download it.

  • SEO Optimization: To maximize the impact, the attackers optimized for search engine keywords, causing these malicious repositories to often rank at the top when users search for terms like "Claude Code leak".

Virus Profile: Vidar Infiltrates, Data "Relocated"

Once users are deceived into downloading and executing the contained executable files, the system is quickly compromised:

  • Information Theft: The implanted Vidar is a highly mature malware on the dark web, specifically designed to harvest browser account passwords, cryptocurrency wallets, and various types of sensitive personal information.

  • Persistent Latency: The virus also simultaneously deploys the GhostSocks proxy tool, setting up a secret channel for subsequent remote control and data exfiltration.

Risk Warning: Beware of "Free Lunches" from Unofficial Channels

Security researchers point out that the malicious compressed files in these fake repositories are updated at an extremely high frequency, making them easy to bypass basic security detection. At least two repositories with similar tactics have been discovered so far, suspected to be tests of different propagation strategies by the same attacker.

Industry Observation: The "Chain Set" of AI Security

From Anthropic's source code packaging mistake to hackers secondarily exploiting the hot topic for phishing, this incident reflects the complexity of security risks in the AI era. When the developer community becomes the target of attacks, basic digital literacy—not running binaries from unknown sources—remains the last line of defense.

Editors remind all developers: Please be sure to obtain tools through official Anthropic channels. Do not fall into the traps carefully designed by hackers out of curiosity or the pursuit of "cracked features."

Пов'язані питання

QWhat is the primary malware being distributed through the fake GitHub repositories related to the Claude Code leak?

AThe primary malware being distributed is called Vidar, which is a sophisticated information-stealing malware known for harvesting browser credentials, cryptocurrency wallets, and other sensitive personal data.

QHow are the attackers making their fake GitHub repositories more visible to potential victims?

AThe attackers are using Search Engine Optimization (SEO) techniques by including popular keywords like 'Claude Code leak' in the repository descriptions, causing these malicious repositories to appear at the top of search results.

QWhat additional tool does the Vidar malware deploy on an infected system to maintain persistence and enable data exfiltration?

AThe Vidar malware also deploys a tool called GhostSocks, which is a proxy utility that creates a secret channel for remote control and ongoing data exfiltration from the compromised system.

QWhat human error at Anthropic initially led to the situation that hackers are exploiting?

AThe initial event was a source code leak of Claude Code caused by a human error at Anthropic, where the code was mistakenly made available, creating the opportunity for hackers to use it as a lure.

QWhat is the main advice from security researchers to developers to avoid falling victim to these traps?

AThe main advice is to only obtain tools through official Anthropic channels and to avoid downloading or running binary files from unverified sources, emphasizing that basic digital hygiene is the last line of defense.

Пов'язані матеріали

Feishu Has Become Doubao

This may be the most important day in the ten-year history of Feishu. On July 30, ByteDance announced a major restructuring via internal email. Feishu, an independent operation for a decade, will no longer function separately and will lose its independent sales and marketing teams. Its product team is being integrated into Doubao AI, and its Go-to-Market strategy merges into the Volcano Engine's To B system. This move signals a strategic pivot, not a failure of Feishu. The era where Feishu sought to be an all-encompassing super-app for productivity is ending. AI has become the dominant logic. Industry trends show a shift from building platform "entrances" to embedding AI directly into workflows, as seen with Microsoft Copilot and Google's Gemini. Data reveals the driver: over 90% of Feishu's new clients in Q2 2026 purchased its AI products. Enterprises are now buying integrated AI solutions, not standalone software. By integrating Feishu's deep enterprise workflow scenarios, Doubao evolves from a consumer-facing chatbot into a powerful enterprise productivity engine. This gives Doubao a critical asset: real-world business application. Concurrently, ByteDance established the "Creative Services Platform," unifying its previously fragmented sales fronts (Feishu, Doubao, Volcano Engine) into a single customer-facing entity. This represents ByteDance's first genuine shift to thinking like a true To B company, organizing around client needs rather than internal product silos. The restructuring underscores that AI is no longer just a business line but foundational infrastructure. Doubao is becoming the new organizational core, mirroring TikTok's past ascendancy. This demonstrates a profound shift: AI is beginning to reshape corporate structures, determining resource allocation and strategic priorities. ByteDance is likely just the first of many companies to undergo such an AI-driven reorganization.

marsbit5 хв тому

Feishu Has Become Doubao

marsbit5 хв тому

The Second Half of the RWA Issuance Race: Amidst the Utilization Dilemma, Trillions Worth of On-Chain Assets Awaken

RWA (Real-World Asset) tokenization has surged to a record $32 billion in on-chain value. However, a structural challenge has emerged: approximately 87% of these tokenized assets are inactive, not participating in DeFi lending or trading activities. This "utilization gap" highlights a key question: what happens after assets are brought on-chain? Data shows a stark contrast among major platforms. While Securitize leads in scale ($4.9B), it has a DeFi utilization rate of only 0.7%. Similarly, Ondo Finance ($3.5B) sees about 2.7% utilization. In contrast, Maple Finance, with a smaller $2.3B in assets, achieves a 62% utilization rate by embedding its assets directly into lending activities from the outset. Three primary factors contribute to low utilization: 1) **Asset Nature**: Tokenized treasuries are often held for yield, not traded. 2) **Regulatory Barriers**: Securities laws and KYC requirements restrict free movement into permissionless DeFi pools. 3) **Infrastructure Gaps**: A lack of deep secondary markets, real-time pricing, and mature clearing mechanisms hinders liquidity. The RWA narrative is now shifting from a "race to issue" to a "battle for application." While native lending protocols like Maple have inherent advantages, distribution channels are becoming critical. The success of products like SyrupUSDG on platforms like Robinhood Crypto demonstrates that access to existing user bases can accelerate adoption far more effectively than protocol-led efforts alone. The $32 billion milestone validates the feasibility of tokenization, but low utilization underscores that bringing assets on-chain is just the first step. The true test for the sector is enabling these assets to circulate, be utilized, and create new economic value within the DeFi ecosystem.

marsbit5 хв тому

The Second Half of the RWA Issuance Race: Amidst the Utilization Dilemma, Trillions Worth of On-Chain Assets Awaken

marsbit5 хв тому

SemiAnalysis on the Epic Plunge: It's Not Over Yet

SemiAnalysis Weekly discusses the recent sharp correction in the semiconductor market after a historic first half. Analysts Doug O'Loughlin and Dylan note that despite healthy fundamentals, markets like South Korea's KOSPI have plunged 40%, wiping out leveraged retail investors. A core debate focuses on AI demand versus supply constraints. Dylan cites SemiAnalysis's internal use of AI coding agents, leading to a 100x increase in AI spending, as evidence of powerful demand. Doug agrees demand is strong but questions its exact magnitude, calling it a "trillion-dollar question." His primary concern is physical and financial bottlenecks: a shortage of 100,000 electricians in the US, massive $450B in corporate debt issuance by hyperscalers (funded by a shrinking pension pool), and labor/scale limits in regions like Taiwan, where TSMC constitutes 20% of GDP. The conversation covers market dynamics, including the typical semiconductor cycle where over-ordering leads to crashes, China's growing memory capacity, and the potential for older chips like the H100 to lose value as models scale. Politically, AI is seen as a likely scapegoat in upcoming elections, though not a top-tier voter priority. The analysts conclude that while the long-term potential is significant, the scaling path is narrowing. The challenge is matching exponential compute demands with real-world constraints on capital, labor, and permits, risking scenarios where massive investment outpaces near-term revenue generation.

marsbit55 хв тому

SemiAnalysis on the Epic Plunge: It's Not Over Yet

marsbit55 хв тому

Торгівля

Спот
活动图片