Anthropic accidentally exposed roughly 512,000 lines of production source code for Claude Code, and attackers quickly turned the leak into a lure for developers seeking “unlocked” or leaked versions of the tool. Researchers reported malicious GitHub repositories repackaging the exposed material and distributing ZIP archives containing a Rust-based dropper that installed Vidar v18.7 information-stealing malware and GhostSocks proxy tooling. One malicious repository reportedly ranked prominently in Google search results for queries related to leaked Claude Code, increasing the chance that developers would download the payloads, while duplicate repositories under different GitHub accounts were linked to the same actor.
The leak also created a broader security risk by exposing Claude Code’s internal architecture, including system prompt construction, tool definitions, safety boundaries, and anti-distillation mechanisms. Because Claude Code can access file systems, execute terminal commands, and modify development environments, researchers warned that disclosure of the full agentic harness gives adversaries a clearer path to craft prompt injections, evade protections, and audit the codebase for exploitable flaws. Those concerns intensified after a critical vulnerability in Claude Code was publicly reported within days of the source exposure, highlighting how the incident expanded the threat surface beyond malware delivery into direct exploitation of organizations using the tool.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
One malicious GitHub repository briefly ranked highly in Google search results for “leaked Claude Code,” increasing the likelihood that developers would download the malware. The campaign leveraged trust signals around GitHub releases and the leaked Claude Code branding.
After the leak, threat actors created malicious GitHub repositories advertising “unlocked” Claude Code versions and distributing a ZIP archive with a Rust-based dropper. Zscaler linked duplicate repositories under different GitHub accounts to the same actor and observed multiple archive variants delivering Vidar v18.7 and GhostSocks.
Within days of the source code leak, a critical vulnerability in Claude Code was publicly reported. Trend Micro says this showed how the leaked code enabled attackers and researchers to systematically audit the codebase for exploitable flaws.
Anthropic accidentally exposed the source code for its Claude Code tool, leaking approximately 512,000 lines of production code. The leak revealed internal implementation details including system prompt construction, tool definitions, safety boundaries, and anti-distillation mechanisms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.