Fake Claude Code Installer Targets Developers With Browser Credential Stealer

https://hackread.com/wp-content/uploads/2026/05/fake-claude-code-installer-devs-browser-credential-stealer-1024x576.jpg

A new report from the Cyber Defence Centre at Ontinue has found a campaign targeting software developers with fake installation pages that look like official sites for AI tools like Claude Code.

The attack begins when a user searches for ‘install Claude code’ and clicks on a sponsored result. This link goes to a lookalike page that shows an installation command. While the real command uses the host ‘claude.ai,’ the fake version uses ‘events.msft23.com.’

Running this command enables Invoke-RestMethod to download a 600 KB, heavily obfuscated PowerShell script. This loader first checks the Windows region settings and stops immediately if the host is located in countries like Russia, Iran, or Ukraine.

But, if the location is not on the list, the malware searches for Chromium-family browsers, including Chrome, Edge, Brave, Vivaldi, Perplexity Comet, Helium, Arc, and Opera, to steal the v20 app_bound_encrypted_key and the v10 encrypted_key, which are keys...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more

https://www.eu-startups.com/wp-content/uploads/2026/05/Untitled-design-2026-05-19T165310.544.jpg

Berlin-based bunch, an AI-native platform for managers and institutional investors to manage the entire fund lifecycle, raised a €30.1M Series B led by Portage

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. Protecting your Cloud Applications Data — Backing up Office 365, Google Workspace, Dropbox & Salesforce data