Skip to main content
Mallory
Back to stories
search-ad-manipulationcredential-stealer-activityai-platform-securityidentity-impersonation-fraud

Malicious and unsafe use of Anthropic Claude Code leading to malware delivery and destructive infrastructure changes

Updated 6d agoFirst seen Mar 9, 202612 sources

Push Security reported an “InstallFix” malvertising campaign targeting developers searching for Anthropic’s Claude Code CLI. Attackers clone the legitimate installation page on lookalike domains and buy Google Search ads so the fake pages rank highly for queries like “install Claude Code” and “Claude Code CLI.” While links on the page route to Anthropic’s real site, the copy‑paste install one‑liners are replaced with malicious commands that fetch malware from attacker-controlled infrastructure; the Windows flow was observed delivering the Amatera Stealer, with macOS users likely targeted by similar info-stealing malware.

Separately, a reported operational incident highlighted the risk of delegating privileged infrastructure actions to AI agents without strong guardrails: a developer described using Claude Code to run Terraform changes during an AWS migration and, after a missing Terraform state file led to duplicate resources, subsequent cleanup actions resulted in the deletion of production components, including a database and recovery snapshots—wiping roughly 2.5 years of records. Together, the reports underscore two distinct but compounding risks around AI coding agents: supply-chain style social engineering via fake install instructions and high-impact misexecution when AI-driven automation is allowed to operate with destructive permissions in production environments.

Share:
Malicious and unsafe use of Anthropic Claude Code leading to malware delivery and destructive infrastructure changes
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

12 events from the earliest known activity through the most recent confirmed update.

12 EVENTS
Mar 7, 20262mo ago

Developer's Claude Code/Terraform run destroys two AWS website environments

During a migration of AI Shipping Labs to AWS infrastructure shared with DataTalks.Club, Alexey Grigorev provided Terraform state late, causing Claude Code to follow that state and execute a Terraform destroy. The action wiped both sites' infrastructure, including a database and snapshots containing about 2.5 years of records.

Grigorev publishes post-mortem and hardening changes

In a post-mortem, Grigorev said he would test restores, add deletion protections and tighter permissions, move Terraform state to S3, and require manual review and execution for destructive actions instead of letting the AI agent run them directly.

Mar 8, 20262mo ago

Amazon Business Support helps restore deleted AWS data

After the destructive Terraform action, Grigorev contacted Amazon Business Support, which assisted with restoring the lost data. The recovery reportedly took about a day.

Mar 9, 20262mo ago

Researchers identify fake Claude Code install pages in Google ads

Security researchers reported a malvertising campaign using lookalike Claude Code installation pages and sponsored Google Search results to trick users into copying malicious install commands. The tactic was described as an "InstallFix" attack that weaponizes trusted one-line terminal commands.

Mar 10, 20262mo ago

Push Security links Windows infection chain to Amatera Stealer

Analysis of the fake Claude Code campaign showed Windows victims were led through a staged execution chain involving cmd.exe and mshta.exe to retrieve attacker-hosted payloads. The resulting malware was identified as Amatera Stealer, an infostealer targeting credentials, cookies, tokens, and system data.

Bitdefender documents Windows and macOS malware from fake Claude Code ads

Bitdefender reported that a fake Claude Code documentation site hosted on a Squarespace subdomain delivered OS-specific malware via ClickFix-style instructions. On Windows it deployed multi-stage stealer payloads, while on macOS it delivered an obfuscated universal Mach-O backdoor capable of remote shell execution.

Google deactivates advertiser account tied to fake Claude Code campaign

Bitdefender said the malicious ad campaign likely used a compromised advertiser account associated with a Malaysian company. Google reportedly deactivated that advertiser account after the abuse was identified.

Apr 15, 20261mo ago

Expel reveals InstallFix scale and MSIX-based Claude Code variant

Expel reported that InstallFix-style fake software install pages had become widespread, accounting for 13% of malware incidents it observed in March 2026, and identified 46 malicious Anthropic-themed webpages over the prior month. The firm also described a GitLab.io-hosted fake Claude Code page that used mshta to fetch a file named claude.msixbundle containing hidden malicious HTML as an anti-analysis technique.

InstallFix: Not the application you were looking for | Expel
May 1, 202617d ago

NordVPN uncovers malware campaign impersonating Google Gemini CLI

NordVPN reported active campaigns using fake websites, cloned repositories, deceptive social posts, and planned typosquatted npm packages to impersonate Google Gemini CLI and trick developers into installing malware. The macOS variant used a Base64-encoded terminal command to download and run a malicious script with elevated privileges, while the Windows variant used a disguised PowerShell fileless attack to provide remote access and enable theft or lateral movement.

Developers warned to avoid 'early-access' Google Gemini tools | IT Pro
May 6, 202612d ago

Gurucul publishes IOCs and detection guidance for InstallFix Claude Code campaign

Gurucul released additional technical analysis of the fake Claude Code InstallFix campaign, describing PowerShell- and mshta-based fileless execution, AMSI bypass, disabled SSL certificate validation, victim-specific command-and-control URLs, and persistence via scheduled tasks. The report also published indicators of compromise and detection queries covering malicious domains, URLs, IPs, hashes, and filenames tied to the activity.

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Community Portal | Gurucul
May 7, 202611d ago

Trend Micro links fake Claude installer campaign to RedLine Stealer activity

Trend Micro reported that the InstallFix-style fake Claude AI installer campaign used paid Google ads and OS-specific social engineering to infect Windows and macOS users, and said the infrastructure and behaviors closely aligned with RedLine Stealer activity. The company also noted observed victims in the United States, Malaysia, the Netherlands, and Thailand across government, education, electronics, and food and beverage sectors.

Hackers Using Fake Claude AI Installer Pages to Trick Users Into Running Malware on Their Systems
May 11, 20267d ago

Ontinue details browser-secret theft in fake Claude Code installer campaign

Ontinue reported an ongoing campaign using sponsored search results and lookalike Claude Code install pages to swap a legitimate one-line installer for an attacker-controlled PowerShell command. The payload abuses Chromium's IElevator2 COM interface to recover encryption keys and decrypt browser-stored cookies, passwords, and payment data, while using Cloudflare-fronted domains and rendered HTML to conceal malicious behavior.

Cookie thieves caught stealing dev secrets
SOURCE COVERAGE

Sources

12 references tracked. Mallory keeps watching after this page renders.

12 SOURCESView all
HackreadNews
May 12, 2026

Fake Claude Code Installer Targets Developers With Browser Credential Stealer

hackread.com

Open source
UnclassifiedNews
May 11, 2026

Behind a Fake Claude Code Installer

ontinue.com

Open source
Register SecurityNews
May 11, 2026

Cookie thieves caught stealing dev secrets

theregister.com

Open source
Cyber Security NewsNews
May 7, 2026

Hackers Using Fake Claude AI Installer Pages to Trick Users Into Running Malware on Their Systems

cybersecuritynews.com

Open source
Gurucul Threat ResearchNews
May 6, 2026

InstallFix and Claude Code: How Fake Install Pages Lead to Real Compromise | Community Portal | Gurucul

community.gurucul.com

Open source
ItproNews
May 1, 2026

Developers warned to avoid 'early-access' Google Gemini tools | IT Pro

itpro.com

Open source
Expel BlogNews
Apr 15, 2026

InstallFix: Not the application you were looking for | Expel

expel.com

Open source
Techrepublic Com SecurityNews
Mar 10, 2026

Fake Claude Code Spreads Malware to Windows, macOS Users - TechRepublic

techrepublic.com

Open source
Bitdefender Labs BlogNews
Mar 10, 2026

Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads

bitdefender.com

Open source
Help Net SecurityNews
Mar 9, 2026

Fake Claude Code install pages highlight rise of "InstallFix" attacks - Help Net Security

helpnetsecurity.com

Open source
Toms HardwareNews
Mar 7, 2026

Claude Code deletes developers' production setup, including its database and snapshots - 2.5 years of records were nuked in an instant | Tom's Hardware

tomshardware.com

Open source
Breakglass IntelNews
Mar 7, 2026

InstallFix: Dissecting a Multi-Stage Infostealer Campaign Hiding Behind Fake Claude Code Installers - Breakglass Intelligence - Breakglass Intelligence

intel.breakglass.tech

Open source
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.