Claude Code leak used to push infostealer malware on GitHub

Threat actors are exploiting the recent Claude Code source code leak by using fake GitHub repositories to deliver Vidar information-stealing malware.

BleepingComputer
New CrystalRAT malware adds RAT, stealer and prankware features

A new malware-as-a-service called CrystalRAT is being promoted on Telegram, offering remote access, data theft, keylogging, and clipboard hijacking capabilities.

BleepingComputer

Claude Code: falsi repository GitHub distribuiscono malware
GitHub è da sempre sfruttata per distribuire malware. Un cybercriminale ha prontamente sfruttato il leak del codice sorgente di Claude Code per creare falsi repository che nascondono il noto infostealer Vidar. È sufficiente una ricerca su Google per finire nella trappola. I repository non sono stati ancora rimossi dalla piattaforma.

#github #malware #claudecode #infostealer #vidar

#sicurezzaonline #repository

https://www.punto-informatico.it/claude-code-falsi-repository-github-distribuiscono-malware/

Claude Code: falsi repository GitHub distribuiscono malware

Un cybercriminale ha creato due repository su GitHub che dovrebbero contenere il codice sorgente di Claude Code, invece nascondono l'infostealer Vidar.

Punto Informatico

📢 Les services de lookup infostealer transforment l'accès initial en cybercriminalité de masse
📝 ## 🌐 Contexte

Article publié le 25 mars 2026 sur infostealers.c...
📖 cyberveille : https://cyberveille.ch/posts/2026-04-02-les-services-de-lookup-infostealer-transforment-l-acces-initial-en-cybercriminalite-de-masse/
🌐 source : https://www.infostealers.com/article/the-new-era-of-initial-access-how-infostealer-lookup-services-are-changing-cybercrime/
#Infostealer #TTP #Cyberveille

Les services de lookup infostealer transforment l'accès initial en cybercriminalité de masse

🌐 Contexte Article publié le 25 mars 2026 sur infostealers.com par Hudson Rock, société spécialisée en cybercrime intelligence. L’article décrit une évolution structurelle du marché de l’accès initial aux systèmes d’information. 🔍 Phénomène observé Des services de lookup de credentials volés par infostealers se sont développés en plateformes centralisées, transformant l’accès initial à des réseaux d’entreprise en une transaction automatisée et bon marché. Ces plateformes agrègent des milliards de credentials compromis et de cookies de session actifs, structurés et interrogeables par URL, login et mot de passe.

CyberVeille

📢⚠️ Hackers are selling “Storm Infostealer,” a tool that bypasses Chrome encryption, steals cookies, hijacks sessions, and targets crypto wallets across browsers.

Read: https://hackread.com/storm-infostealer-sold-as-service-browsers-wallets/

#CyberSecurity #Malware #Infostealer #Chrome

Storm Infostealer Sold as Service, Targets Browsers, Wallets and Accounts

Hackers are selling Storm Infostealer, a tool that bypasses Chrome encryption to steal cookies, credentials, crypto wallets and accounts across browsers.

Hackread - Cybersecurity News, Data Breaches, AI and More

Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka

Pulse ID: 69ca1c3f020aa0849dc313f0
Pulse Link: https://otx.alienvault.com/pulse/69ca1c3f020aa0849dc313f0
Pulse Author: Tr1sa111
Created: 2026-03-30 06:46:23

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #OTX #OpenThreatExchange #Python #bot #Tr1sa111

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange

Torg Grabber: nuovo malware per furto di criptovalute
I ricercatori di Gen Digital hanno individuato un nuovo #malware denominato #torggrabber che viene sfruttato principalmente per rubare #criptovalute Si tratta quindi di un #infostealer ma offre funzionalità più avanzate rispetto ai suoi simili. Può utilizzare diverse tecniche di infezione e modalità di esfiltrazione dei dati.

@sicurezza

https://www.punto-informatico.it/torg-grabber-nuovo-malware-furto-criptovalute/

Torg Grabber: nuovo malware per furto di criptovalute

Torg Grabber è un nuovo infostealer per Windows che sfrutta varie tecniche di infezione e può rubare le criptovalute da 728 estensioni di browser.

Punto Informatico
Suspected RedLine infostealer malware admin extradited to US

An Armenian suspect was extradited to the United States to face criminal charges for allegedly helping manage RedLine, one of the most prolific infostealer malware operations in recent years.

BleepingComputer

Infiniti Stealer: a new macOS infostealer using ClickFix and Python/Nuitka

A new macOS infostealer called Infiniti Stealer has been discovered, utilizing ClickFix delivery and Python/Nuitka compilation. The malware spreads through a fake CAPTCHA page, tricking users into running a command themselves. The final payload is a Python-based stealer compiled with Nuitka, making it harder to analyze and detect. The malware targets sensitive data including browser credentials, macOS Keychain entries, cryptocurrency wallets, and developer files. It employs anti-analysis techniques and exfiltrates data via HTTP POST requests. This campaign demonstrates the adaptation of Windows-based techniques to target Mac users and showcases the increasing sophistication of macOS malware.

Pulse ID: 69c65110c392e209625c97d5
Pulse Link: https://otx.alienvault.com/pulse/69c65110c392e209625c97d5
Pulse Author: AlienVault
Created: 2026-03-27 09:42:40

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Browser #CAPTCHA #CyberSecurity #HTTP #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #Python #RAT #Windows #bot #cryptocurrency #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
New Torg Grabber infostealer malware targets 728 crypto wallets

A new info-stealing malware called Torg Grabber is stealing sensitive data from 850 browser extensions, more than 700 of them for cryptocurrency wallets.

BleepingComputer