Threat actors are abusing interest in AI developer tools by impersonating installers and setup guides to trick users into executing malware. Fake installation-guide pages for Anthropic’s Claude Code were promoted via Google Ads to rank highly for searches like “Claude Code install/CLI,” leading Windows and macOS users to run copy-pasted commands in an InstallFix campaign (a variant of ClickFix) that ultimately deployed Amatera (an ACR Stealer-based MaaS infostealer). Push Security reported the malware steals browser-stored credentials, cookies, session tokens, and system information, and the infrastructure used legitimate hosting/CDN services (e.g., Squarespace, Cloudflare Pages, Tencent EdgeOne) to reduce suspicion.
In a related AI-tool impersonation theme, JFrog identified a malicious npm package, @openclaw-ai/openclawai, posing as an OpenClaw installer that targets macOS users to steal credentials and establish persistent remote access. The package uses a postinstall hook to reinstall itself globally and registers a CLI via the bin field pointing to scripts/setup.js, which presents a fake installer UI and then prompts for the user’s system password via a bogus Keychain/iCloud authorization flow. The malware (self-identified as GhostLoader) was reported to collect browser data, crypto wallets, SSH keys, Apple Keychain databases, and iMessage history, while also deploying a RAT with SOCKS5 proxy capability and “live browser session cloning,” indicating a blend of credential theft and long-term access objectives.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
ThreatLabz identified a malicious GitHub campaign that used a fake 'Claude Code leak' repository and release archives to lure users into downloading a Rust-based dropper, ClaudeCode_x64.exe. The malware deployed Vidar v18.7 and GhostSocks, and the actor also operated a second similar repository while benefiting from high Google search visibility for 'leaked Claude Code' queries.
The Amatera campaign was found to host malicious pages on legitimate infrastructure including Squarespace, Cloudflare Pages, and Tencent EdgeOne to improve stealth and resilience. The report also linked the activity to a broader pattern of fake developer-tool installers, noting recent OpenClaw-themed lures promoted through Bing AI search results.
Push Security reported a new InstallFix campaign using fake Anthropic Claude Code installation pages promoted through Google Ads malvertising. The campaign targeted Windows and macOS users and delivered the Amatera infostealer, which steals browser credentials, cookies, session tokens, and system information.
Analysis revealed the package fetched an encrypted second-stage JavaScript payload from trackpipe[.]dev, identified internally as GhostLoader. The malware acted as a full-featured macOS infostealer and RAT with persistence, SOCKS5 proxying, command execution, browser session cloning, and exfiltration via its C2 server, Telegram Bot API, and GoFile.io.
Researchers reported that the npm package @openclaw-ai/openclawai impersonated an OpenClaw installer and used a postinstall hook to deploy a macOS-focused malware chain. The package reinstalled itself globally, displayed a fake CLI installer, and used a bogus iCloud Keychain prompt to trick victims into entering their system password.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourcescworld.com
Open sourcepillar.security
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.