Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Claude Code source leak exploited to spread malware
    Cybersecurity

    Claude Code source leak exploited to spread malware

    adminBy adminApril 4, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Claude Code source leak exploited to spread malware
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A source code leak involving Anthropic’s Claude Code tool quickly escalated into a cybersecurity threat, as attackers seized on the exposed files to lure developers into downloading malware disguised as “unlocked” versions of the software.

    Leaked Claude Code source code used as lure

    On March 31, 2026, Anthropic accidentally exposed online the source code of its Claude Code tool. The leak was detected by security researcher Chaofan Shou, whose post on X drew widespread attention.

    The leaked map file contained about 513,000 lines of unobfuscated TypeScript in 1,906 files, revealing the client-side agent framework. Within hours, the code was downloaded, mirrored on GitHub, and redistributed, with some repositories gaining tens of thousands of stars and forks.

    While monitoring GitHub for threats, Zscaler researchers identified a repository titled “Leaked Claude Code” published by a user named idbzoomh1.

    Its README.md file claims the material was obtained from a .map file embedded in an npm package and then reconstructed into a functional fork, described as having “unlocked” Claude Code’s enterprise features and no message limits.

    “The malicious ZIP archive in the repository’s releases section is named Claude Code – Leaked Source Code (.7z),” the researchers said.

    “The archive includes ClaudeCode_x64.exe, a Rust-based dropper. On execution, the ClaudeCode_x64.exe drops Vidar v18.7 and GhostSocks. Vidar is an information stealer and GhostSocks is used to proxy network traffic.”

    Before it was removed, the link to the malicious repository appeared near the top of Google search results for users looking for “leaked Claude Code”.

    Claude Code GitHub malware

    Google search results for leaked Claude Code on GitHub returning a malicious repository (Source: Zcaler)

    During their analysis, Zscaler observed the threat actor uploading two separate versions of the malicious ZIP archive to the repository’s releases section within a short timeframe.

    The same GitHub repository was also identified under a different account (my3jie), containing identical code and appearing to be linked to the same threat actor.

    A hot tool makes for a good lure

    The popularity of Claude Code makes it a good lure for scammers, malware peddlers, and other attackers.

    Earlier this month, Push Security warned about fake/cloned Claude Code install pages that were pushing malware and were popping up in Google Search results.

    After pointing out that leaked proprietary source code is not “open source”, the researchers advised users against downloading, forking, building, or running code from any GitHub repository claiming to be the “leaked Claude Code.”

    “Verify every source against Anthropic’s official channels only,” they counseled, and shared indicators of compromise linked to this campaign.

    Claude Code Exploited leak Malware Source spread
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleThis is the one DDR5 RAM deal you don’t want to miss
    Next Article NYT Strands hints and answers for Saturday, April 4 (game #762)
    admin
    • Website

    Related Posts

    Lawmakers Gathered Quietly to Talk About AI. Angst and Fears of ‘Destruction’ Followed

    April 18, 2026

    Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

    April 18, 2026

    How Threat Actors Vet Stolen Credit Card Shops

    April 18, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Google Meet gets the upgrade we’ve all been waiting for

    April 18, 2026

    Lawmakers Gathered Quietly to Talk About AI. Angst and Fears of ‘Destruction’ Followed

    April 18, 2026

    Why bottom-of-funnel content is winning in AI search

    April 18, 2026

    Missed your shot at a Galaxy Z TriFold? A successor could be in the works with a new hinge

    April 18, 2026
    Categories
    • Blogging (65)
    • Cybersecurity (1,379)
    • Privacy & Online Earning (171)
    • SEO & Digital Marketing (845)
    • Tech Tools & Mobile / Apps (1,648)
    • WiFi / Internet & Networking (231)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Google Meet gets the upgrade we’ve all been waiting for

    April 18, 2026

    Lawmakers Gathered Quietly to Talk About AI. Angst and Fears of ‘Destruction’ Followed

    April 18, 2026

    Why bottom-of-funnel content is winning in AI search

    April 18, 2026
    Most Popular
    • Google Meet gets the upgrade we’ve all been waiting for
    • Lawmakers Gathered Quietly to Talk About AI. Angst and Fears of ‘Destruction’ Followed
    • Why bottom-of-funnel content is winning in AI search
    • Missed your shot at a Galaxy Z TriFold? A successor could be in the works with a new hinge
    • This Compact HP Mini Desktop Is on Sale for Just $320 Right Now
    • Data centers are costing local governments billions
    • Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet
    • This open-source smart home system is slowly overtaking Alexa and Google Home
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.