spot_img

Date:

Share:

Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools

In March 2026, Kaspersky Threat Research has identified a new malicious campaign targeted at developers looking for installation instructions for Claude Code, a development agent created by Anthropic. When searching for “Claude Code download”, sponsored advertisements appear at the top of the search results. One of these ads redirects users to a malicious webpage that closely imitates the official installation documentation for Claude Code. As a result, users are tricked into installing malware which harvests sensitive information including credentials, crypto wallet data, browser sessions, and other confidential files. Similar malicious campaigns mimic other popular AI tools, including OpenClaw.

The fake documentation page is visually identical to the legitimate one and is hosted on the website-building and hosting platform Squarespace. Because the page precisely copies the original instructions, users may not notice the difference when copying and executing installation commands.

 Kaspersky discovers infostealers mimicking Claude Code, OpenClaw and other AI developer tools

However, instead of installing the developer tool, the commands deliver malware to the victim’s system. Depending on the operating system, the malicious commands deploy different infostealers:

  • Windows systems receive Amatera, an information-stealing malware that collects data from user directories, web browsers, and cryptocurrency wallets before sending the stolen information to a remote server. Amatera has previously been observed in campaigns using the ClickFix distribution technique and is operated under a Malware-as-a-Service (MaaS) model.
  • macOS systems receive AMOS, another infostealer previously documented in several malware campaigns targeting Apple devices. It has been described by Kaspersky before.

Kaspersky researchers also identified similar malicious campaigns targeting other popular AI tools, including OpenClaw and Doubao. Using the same approach, attackers registered multiple domains and distributed files containing the Amatera infostealer while disguising them as legitimate downloads for these tools.

“The campaign poses significant risks because AI development tools such as Claude Code and OpenClaw are widely used not only by hobbyists and automation enthusiasts but also by professional developers working in large organisations. If infected, victims may unknowingly expose source code from active projects, confidential corporate data, authentication credentials, and private accounts. This makes such campaigns particularly dangerous for businesses whose developers rely on AI-assisted coding tools,” comments Vladimir Gursky, cybersecurity expert at Kaspersky.

In December 2025, Kaspersky detected that attackers spread a macOS infostealer using Google Ads. A specially generated chat interface designed to resemble a ChatGPT tutorial pretended to guide users through installing the Atlas Browser. The malicious instructions appeared to be hosted on a legitimate site associated with OpenAI, helping attackers gain users’ trust.

To stay protected, Kaspersky recommends:

  • Carefully verify download links and ensure they point to official project websites.
  • Review any command-line instructions before executing them, especially if copied from external sources.
  • Avoid following guides you did not specifically request or do not fully understand.
  • Use reliable endpoint security solutions capable of detecting and blocking infostealers and malicious downloads.
spot_img
spot_img

━ More like this

From Data to Decisions: Threat Intelligence in SOC operations

Effective analysis starts with the essential questions “who, what, when, where, why and how” - that convert data into intelligence. In many ways, these...

Kaspersky and AFRIPOL conduct joint cybersecurity training for African law enforcement

As part of a joint initiative with AFRIPOL, Kaspersky provided cybersecurity training courses for law enforcement representatives from 23 African countries, unfolding the fundamentals...

Westcon-Comstor expands cybersecurity and networking portfolio with Infoblox in Southern Africa

New partnership brings hybrid, multi-cloud networking and pre-emptive security expertise to regional channel partners Westcon-Comstor, a global technology distributor specialising in cybersecurity, networking and hybrid...

Qualified cybersecurity staff shortage among key obstacles in curbing supply chain risks

A new global Kaspersky study has identified the lack of qualified IT security workers and the need for global organisations to prioritise various security...

Kenya: Court of Appeal upholds cybercrime law but strikes down ‘fake news’ offences

On 6 March 2026, the Court of Appeal in Nairobi (Court) issued a landmark decision on the Computer Misuse and Cybercrimes Act (2018) (Act)....
spot_img