TechBooky AI Assistant
TechBooky AI Assistant
👋 Welcome to TechBooky AI Assistant

I can help with:
🔎 Tech News
🤖 AI Topics
💻 Gadgets
☁️ Cloud
✍️ Guest Posts
📢 Advertising
🔗 Backlinks
📩 Newsletter
  • AI Search
  • Cryptocurrency
  • Earnings
  • Enterprise
  • About TechBooky
  • Submit Article
  • Advertise With TechBooky
  • Contact Us
TechBooky
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • AI
  • Metaverse
  • Gadgets
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
TechBooky
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
Home Artificial Intelligence

Leaked & Exploited Claude Code Distributes Infostealer Malware On GitHub

Akinola Ajibola by Akinola Ajibola
April 3, 2026
in Artificial Intelligence
Share on FacebookShare on Twitter
Share this story

Send it to someone who should read it.

f Facebook X X in LinkedIn wa WhatsApp tg Telegram @ Email

In Brief
  • In order to spread Vidar information-stealing malware, threat actors are taking advantage of the recent Claude Code source code breach by creating phony GitHub repositories.
  • Threat actors are now employing phony GitHub repositories and malicious Google Ads to spread infostealer malware that poses as “leaked” or “unlocked” versions of Claude Code...
  • Claude Code is an Anthropic terminal-based AI agent that is capable of direct system contact, LLM API call processing, MCP integration, and permanent memory.

In order to spread Vidar information-stealing malware, threat actors are taking advantage of the recent Claude Code source code breach by creating phony GitHub repositories.

Threat actors are now employing phony GitHub repositories and malicious Google Ads to spread infostealer malware that poses as “leaked” or “unlocked” versions of Claude Code in the wake of Anthropic’s enormous unintentional source code leak on March 31, 2026.

Claude Code is an Anthropic terminal-based AI agent that is capable of direct system contact, LLM API call processing, MCP integration, and permanent memory. It is intended to carry out coding activities directly in the terminal and function as an autonomous agent.

Last Tuesday, March 31st, Anthropic unintentionally included a 59.8 MB JavaScript source map in the published npm package, exposing the whole client-side source code of the new tool.

Attackers are exploiting the Claude Code leak to trick developers into installing malware. They use fake websites, GitHub repos, and Google ads to deliver info-stealers (Vidar, Amatera, AMOS) and proxy malware (GhostSocks). A separate npm supply chain attack on the axios package on March 31 may have also compromised users.

The breach included 1,906 files with 513,000 lines of unobfuscated TypeScript that exposed the agent’s execution systems, rights, orchestration logic, hidden features, development information, and security-related internals.

Many others quickly downloaded the leaked code, which was then posted on GitHub and forked thousands of times.

The disclosure gave threat actors a chance to distribute the Vidar infostealer to people searching for the Claude Code leak, according to a report from cloud security firm Zscaler.

The researchers discovered that a fraudulent GitHub repository created by user “idbzoomh” posted a phony leak and promoted it as having no usage limitations and “unlocked enterprise features.”

Also worth reading
Anthropic J-Lens Reveals How Claude Organises Its Hidden Reasoning US Orders Anthropic to Disable Claude Fable 5 and Mythos 5 Over National Security Concerns Anthropic Launches Claude Fable 5, Bringing Mythos-Class AI to the Public AI Coding Tools Are Creating A New Burden For Open-Source Maintainers Paystack AI Checkout: How Agentic Payments Could Change Nigeria Apple’s OpenAI Lawsuit Turns The AI Hardware Race Into A Legal Fight

The repository is tailored for search engines and appears among the top results on Google Search for phrases like “leaked Claude Code” in order to increase traffic to the fake leak.

The researchers claim that inquisitive individuals download a 7-Zip file containing ClaudeCode_x64.exe, a Rust-based executable. The dropper launches the GhostSocks network traffic proxying tool and Vidar, a commodity information stealer.

Zscaler found that the malicious archive is often updated, indicating that future iterations might include additional payloads.

A second GitHub repository with the same code was also discovered by the researchers; however, at the time of study, it displayed a “Download ZIP” button. According to Zscaler, it is run by the same threat actor who probably tests different distribution methods.

GitHub has frequently been exploited to disseminate malicious payloads that are disguised in different ways, despite the platform’s protections.

Threat actors used repositories purporting to include proof-of-concept (PoC) exploits for recently discovered vulnerabilities to target novice researchers or cybercriminals in campaigns in late 2025.

In the past, attackers were eager to take advantage of well-publicized incidents in the hopes of making advantageous concessions.

Additional details to this show that the leak wasn’t a hack and that it was Anthropic’s packaging mistake. They accidentally included a 60MB source map file in an npm package, exposing ~512,000 lines of TypeScript code. Within hours, the code spread worldwide, was analyzed, and rewritten in other languages to evade DMCA takedowns.

Avoid unofficial “leaked” Claude Code repositories that don’t download, fork, or run anything from them. Stick to Anthropic’s official site or verified npm page for installation. If you touched any suspicious repos on March 31, 2026, rotate all your API keys and credentials immediately.

Related Reading

More contextual TechBooky stories selected from tags, categories and article context.

  • claude code leak
    Claude Code Leak Raises Bigger Question; Can AI…
  • Claude-Code
    Claude Code Source Leak Hints at ‘Proactive’ Mode…
  • github
    GitHub Confirms Hackers Stole Data From About 3,800…
  • ms claude
    Microsoft Initiates Claude Code Licenses Termination
  • anthropic
    Anthropic’s Claude Opus 4.6 Debuts 1M-Token Context
  • AI_Risks-ChatGPT
    OpenAI Confirms Hack Linked to TanStack Attack
  • deepkeep
    New CLI Tool Exposes Blind Spot in AI Agent Security…
  • Screenshot 2024-10-03 at 15.34.40
    GitHub Copilot Surpasses 15 Million Users
Keep Reading Smarter

Search TechBooky with AI

Use TechBooky's AI Search to explore the context behind this story and related coverage across the site.

Try AI Search
More On This Topic
Artificial Intelligence
Follow TechBooky

Follow TechBooky for more technology stories and newsroom updates.

f Facebook X X in LinkedIn ig Instagram wa WhatsApp

Tags: AIclaude code leakcodegithub
Akinola Ajibola

Akinola Ajibola

Search TechBooky
Open TechBooky AI Search Try the AI Assistant

BROWSE BY CATEGORIES

Receive top tech news directly in your inbox

subscription from
Loading

Freshly Squeezed

  • Rivian Spinout ALSO Turns E-Bikes Into An Autonomous Delivery Bet August 23, 2026
  • Apple’s Foldable iPhone May Be Real, But The Trade-Offs Are Too August 23, 2026
  • Apple Job Cuts Point To A New Siri And Vision Pro Reset August 22, 2026
  • TikTok’s $400M Privacy Settlement Shows Child Safety Costs Are Rising August 22, 2026
  • OpenAI Cuts GPT-5.6 Sol API Prices As AI Price War Deepens August 22, 2026
  • Apollo Data Breach Shows Wall Street’s Cloud Security Problem August 21, 2026
  • Tesla’s China Recall Turns Hidden Door Handles Into A Safety Issue August 21, 2026
  • Oura Lawsuit Puts AI Sleep Tracking Under Legal Pressure August 21, 2026
  • Ericsson And MTN Move MoMo Onto Cloud Across Four Markets August 21, 2026
  • Kenya’s Digital ID Talks Put Trust Back At The Centre August 21, 2026
  • Starcloud’s $250M Raise Pushes Orbital AI Data Centres Closer August 21, 2026
  • Micron’s $10B Boise Lab Makes Memory A Bigger AI Battleground August 21, 2026

Browse Archives

August 2026
M T W T F S S
 12
3456789
10111213141516
17181920212223
24252627282930
31  
« Jul    

Quick Links

  • About TechBooky
  • Advertise With TechBooky
  • Contact us
  • Submit Article
  • Privacy Policy
Generic selectors
Exact matches only
Search in title
Search in content
Post Type Selectors
Search in posts
Search in pages
  • African
  • Artificial Intelligence
  • Gadgets
  • Metaverse
  • Tips
  • AI Search
  • About TechBooky
  • Advertise With TechBooky
  • Submit Article
  • Contact us

© 2025 Designed By TechBooky Elite

Discover more from TechBooky

Subscribe now to keep reading and get access to the full archive.

Continue reading

We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.