Prnewswire Bybit Exposes Multi-Stage Malware Targeting Claude Code Users
Article Content
- •Bybit identified a malware campaign targeting macOS users searching for Claude Code.
- •The attack used SEO poisoning to redirect users to malicious installation pages.
- •The malware chain involved credential harvesting and persistent access through advanced techniques.
Bybit's Security Operations Center (SOC) reported a sophisticated malware campaign targeting macOS users searching for 'Claude Code,' an AI development tool from Anthropic. The campaign, first identified in March 2026, employed SEO poisoning to redirect users to a malicious installation page resembling legitimate documentation. The attack involved a two-stage malware chain, with the initial payload delivered via a Mach-O dropper, deploying an osascript-based infostealer that extracted sensitive data such as browser credentials and cryptocurrency wallet information. The second-stage payload introduced a C++ backdoor with advanced evasion techniques, allowing persistent access and remote command execution. Bybit's SOC utilized AI-assisted workflows to expedite malware analysis and detection, achieving significant reductions in response times. The campaign targeted over 250 browser wallet extensions and multiple desktop wallet applications, highlighting the threat to developers in the cryptocurrency sector.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (5)
Following this threat?
Track AMOS and Ledger in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Infostealer Malware Hijacks Claude Sessions, Drains User Accounts Anthropic has alerted users that infostealer malware is compromising Claude accounts by hijacking active login sessions, allowing attackers to deplete usage limits without needing passwords or two-factor authentication. The malware, identified as Vidar, LummaC2, StealC, RedLine, and Acreed on Windows, and Atomic…
Fake Codex Installer Delivers Suspected AMOS Infostealer via Google Sites A malicious campaign has emerged, using fake Codex installation pages to deliver malware targeting macOS users. The attackers utilize Google Sites to host a fraudulent download portal that appears legitimate, tricking users into executing a command that initiates a multi-stage malware infection. The command, disguised…