Home
Critical Leak of Claude Code Source Ignites Secondary Cyber Threats via GitHub Phishing Ploy

According to a report dated April 2nd, the ongoing leak of Claude Code source code, initiated by a human error at Anthropic, is being exploited by threat actors. They are currently leveraging this high-profile incident to distribute a data-stealing malware known as Vidar via fraudulent GitHub repositories.
Evolving Bait: Promises of "Unlocking Enterprise Features"
Monitoring reports from security firm Zscaler reveal that a user named "idbzoomh" has created multiple counterfeit repositories on the platform.
Targeted Lures: In the repository descriptions, the attacker claims to offer leaked source code that unlocks enterprise-level functionalities, tempting developers eager to experiment with the code into downloading it.
Search Engine Manipulation: To maximize reach, the attacker employed search engine optimization (SEO) tactics, causing these malicious repositories to frequently rank at the top of search results for terms like "Claude Code leak."
Malware Analysis: Vidar Infiltration and Data Exfiltration
Once a user takes the bait and executes the downloaded files, their system is swiftly compromised.
Comprehensive Data Theft: The embedded Vidar malware is a well-established threat on dark web markets, specifically designed to harvest browser-saved passwords, cryptocurrency wallets, and various other sensitive personal data.
Persistent Backdoor: The malware also deploys the GhostSocks proxy tool to establish covert communication channels, enabling subsequent remote control and ongoing data exfiltration.
Security Advisory: Scrutinize "Free Offers" from Unofficial Sources
Security researchers note that these fake repositories are updated at a remarkably high frequency, a tactic that helps them evade basic security scans. At least two similar repositories have been identified, indicating these may be test campaigns by the same attacker using varied distribution methods.
Industry Perspective: The AI Era's Security Chain
From the initial Anthropic source code packaging error to hackers capitalizing on the news for phishing, this incident highlights the complex security landscape of the AI era. With the developer community becoming a prime target, fundamental digital hygiene—such as never executing binaries from untrusted sources—remains a critical last line of defense.
A Final Note to Developers: Always acquire tools and software through Anthropic 's official channels. Do not let curiosity or the allure of "cracked features" lead you into traps meticulously set by cybercriminals.
Related article
AI Browser Comet Launches with Full Multitasking Support on iPad
Perplexity’s AI browser, Comet, has officially launched its iPad version, now fully compatible with iPadOS. The update introduces multi-window browsing, multitasking support, and deep integration with leading AI models like OpenAI and Anthropic, deli
Trace raises $3M to tackle enterprise AI agent adoption hurdles
Despite their potential, AI agents have struggled to gain traction in the enterprise. One emerging startup believes the core issue is a lack of context.Launched as part of Y Combinator’s 2025 summer cohort, Trace is a workflow orchestration startup d
Google IO 2026 unveils voice interaction with Gmail inbox
Google continues to integrate AI into your inbox. At the IO 2026 developer conference on Tuesday, the company expanded its Gmail "AI Inbox" feature with conversational AI, allowing users to ask questions about their inbox content rather than relying
Related Special Topic Recommendations
Comments (0)
0/500

According to a report dated April 2nd, the ongoing leak of
Evolving Bait: Promises of "Unlocking Enterprise Features"
Monitoring reports from security firm Zscaler reveal that a user named "idbzoomh" has created multiple counterfeit repositories on the platform.
Targeted Lures: In the repository descriptions, the attacker claims to offer leaked source code that unlocks enterprise-level functionalities, tempting developers eager to experiment with the code into downloading it.
Search Engine Manipulation: To maximize reach, the attacker employed search engine optimization (SEO) tactics, causing these malicious repositories to frequently rank at the top of search results for terms like "Claude Code leak."
Malware Analysis: Vidar Infiltration and Data Exfiltration
Once a user takes the bait and executes the downloaded files, their system is swiftly compromised.
Comprehensive Data Theft: The embedded Vidar malware is a well-established threat on dark web markets, specifically designed to harvest browser-saved passwords, cryptocurrency wallets, and various other sensitive personal data.
Persistent Backdoor: The malware also deploys the GhostSocks proxy tool to establish covert communication channels, enabling subsequent remote control and ongoing data exfiltration.
Security Advisory: Scrutinize "Free Offers" from Unofficial Sources
Security researchers note that these fake repositories are updated at a remarkably high frequency, a tactic that helps them evade basic security scans. At least two similar repositories have been identified, indicating these may be test campaigns by the same attacker using varied distribution methods.
Industry Perspective: The AI Era's Security Chain
From the initial
A Final Note to Developers: Always acquire tools and software through
AI Browser Comet Launches with Full Multitasking Support on iPad
Perplexity’s AI browser, Comet, has officially launched its iPad version, now fully compatible with iPadOS. The update introduces multi-window browsing, multitasking support, and deep integration with leading AI models like OpenAI and Anthropic, deli
Trace raises $3M to tackle enterprise AI agent adoption hurdles
Despite their potential, AI agents have struggled to gain traction in the enterprise. One emerging startup believes the core issue is a lack of context.Launched as part of Y Combinator’s 2025 summer cohort, Trace is a workflow orchestration startup d
Google IO 2026 unveils voice interaction with Gmail inbox
Google continues to integrate AI into your inbox. At the IO 2026 developer conference on Tuesday, the company expanded its Gmail "AI Inbox" feature with conversational AI, allowing users to ask questions about their inbox content rather than relying











