A trojanized GitHub project advertising a free “Claude Opus 5 Free Desktop” client is distributing the Windows-based RevStealer information stealer. The malicious Electron application performs host profiling and anti-analysis checks before decrypting a native payload into a randomly named AppData directory; the payload adds anti-VM scoring, regional targeting exclusions, and a CAPTCHA gate. Operators have also used game-cheat-themed websites to deliver the malware, demonstrating reuse across multiple social-engineering lures.
RevStealer targets browser passwords, cookies and sessions, cryptocurrency wallets, password-manager data, VPN and remote-access settings, messaging and gaming artifacts, screenshots, clipboard contents, and selected documents. It seeks to minimize forensic traces through runtime decryption, import-less API resolution, indirect syscalls, encrypted streaming exfiltration, attempted Microsoft Defender exclusions, and self-deletion rather than persistence. When its primary command-and-control infrastructure is unavailable, the malware can obtain fallback C2 details from a Polygon smart contract.

Pull IOCs and campaign context straight into your stack.
6 events from the most recent confirmed update back to the earliest known activity.
Joe Security attributed an NSIS-packaged Electron application named ClaudeMythos.exe to ScarfaceStealer and documented its multi-stage loader and weighted 11-indicator anti-analysis system. The sample used check.mentor-square80.click:443 as C2 and could retrieve the same encrypted C2 value from a Polygon smart contract.
Elastic Security Labs documented four executables linked to REVSTEALER through shared code, packing, infrastructure, and Polygon smart-contract backup-C2 tradecraft. The independently persistent modules support wallet-overlay theft, crypto-address clipboard hijacking, reverse-proxy abuse, and cryptomining that disables Windows Update services and adds Microsoft Defender exclusions; Elastic did not observe REVSTEALER delivering them on live victim systems.
A victim cited in the reporting said their Microsoft and EA accounts were compromised shortly after they executed the malicious Claude Opus 5 download that delivered RevStealer.
Morphisec disclosed that RevStealer uses an invisible Electron loader, layered sandbox and debugger checks, runtime API resolution, encrypted configuration, and indirect syscalls. The stealer exfiltrates collected data from memory, can retrieve a fallback C2 address from a Polygon smart contract, and bypasses Chromium App-Bound Encryption through debugger-controlled browser processes.
Morphisec observed RevStealer also being distributed through game-cheat-themed websites, indicating the operators reused the stealer across multiple social-engineering lures.
Threat actors distributed the RevStealer Windows information stealer through a trojanized “Claude Opus 5 Free Desktop” GitHub project impersonating Anthropic. The campaign used a nonfunctional Electron application to deliver a native payload that steals credentials, cryptocurrency-wallet data, and other user information.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 34 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
7 references tracked. Mallory keeps watching after this page renders.
thehackernews.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourceelastic.co
Open sourcemorphisec.com
Open sourcejoesecurity.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.