Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
credential-stealer-activitypackage-repository-poisoningsearch-ad-manipulationremote-access-implant

Malvertising and Supply-Chain Lures Impersonate AI Developer Tools to Deliver Infostealers and RATs

Updated 3mo agoFirst seen Mar 10, 20264 sources

Threat actors are abusing interest in AI developer tools by impersonating installers and setup guides to trick users into executing malware. Fake installation-guide pages for Anthropic’s Claude Code were promoted via Google Ads to rank highly for searches like “Claude Code install/CLI,” leading Windows and macOS users to run copy-pasted commands in an InstallFix campaign (a variant of ClickFix) that ultimately deployed Amatera (an ACR Stealer-based MaaS infostealer). Push Security reported the malware steals browser-stored credentials, cookies, session tokens, and system information, and the infrastructure used legitimate hosting/CDN services (e.g., Squarespace, Cloudflare Pages, Tencent EdgeOne) to reduce suspicion.

In a related AI-tool impersonation theme, JFrog identified a malicious npm package, @openclaw-ai/openclawai, posing as an OpenClaw installer that targets macOS users to steal credentials and establish persistent remote access. The package uses a postinstall hook to reinstall itself globally and registers a CLI via the bin field pointing to scripts/setup.js, which presents a fake installer UI and then prompts for the user’s system password via a bogus Keychain/iCloud authorization flow. The malware (self-identified as GhostLoader) was reported to collect browser data, crypto wallets, SSH keys, Apple Keychain databases, and iMessage history, while also deploying a RAT with SOCKS5 proxy capability and “live browser session cloning,” indicating a blend of credential theft and long-term access objectives.

Share:
Malvertising and Supply-Chain Lures Impersonate AI Developer Tools to Deliver Infostealers and RATs
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Apr 1, 20263mo ago

ThreatLabz finds fake Claude Code leak repo spreading Vidar and GhostSocks

ThreatLabz identified a malicious GitHub campaign that used a fake 'Claude Code leak' repository and release archives to lure users into downloading a Rust-based dropper, ClaudeCode_x64.exe. The malware deployed Vidar v18.7 and GhostSocks, and the actor also operated a second similar repository while benefiting from high Google search visibility for 'leaked Claude Code' queries.

Anthropic Claude Code Leak | ThreatLabz
Mar 10, 20263mo ago

InstallFix campaign found using legitimate hosting providers for stealth

The Amatera campaign was found to host malicious pages on legitimate infrastructure including Squarespace, Cloudflare Pages, and Tencent EdgeOne to improve stealth and resilience. The report also linked the activity to a broader pattern of fake developer-tool installers, noting recent OpenClaw-themed lures promoted through Bing AI search results.

Push Security reports fake Claude Code guides spreading Amatera

Push Security reported a new InstallFix campaign using fake Anthropic Claude Code installation pages promoted through Google Ads malvertising. The campaign targeted Windows and macOS users and delivered the Amatera infostealer, which steals browser credentials, cookies, session tokens, and system information.

Mar 9, 20264mo ago

GhostLoader second-stage malware capabilities are disclosed

Analysis revealed the package fetched an encrypted second-stage JavaScript payload from trackpipe[.]dev, identified internally as GhostLoader. The malware acted as a full-featured macOS infostealer and RAT with persistence, SOCKS5 proxying, command execution, browser session cloning, and exfiltration via its C2 server, Telegram Bot API, and GoFile.io.

Researchers identify malicious npm package posing as OpenClaw installer

Researchers reported that the npm package @openclaw-ai/openclawai impersonated an OpenClaw installer and used a postinstall hook to deploy a macOS-focused malware chain. The package reinstalled itself globally, displayed a fake CLI installer, and used a bogus iCloud Keychain prompt to trick victims into entering their system password.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

64 LINKEDOpen in app
Threat actors
1 linked
Affected products
19 linked
GithubGoogle SearchClaude CodeBingOpenclawMacosWindowsYandex BrowserSafariImessageBrave BrowserVisual Studio CodeChatgptKubernetesTerminalDockerOperaDeepseekChrome
Organizations
30 linked
GoogleAnthropicGitHubMicrosoft CorporationZscalerSquarespaceOpenaiCodeiumAnysphereTencentReplitBleepingComputerAmazon Web ServicesJfrogDeepseekBrave SoftwareCloudflarePush SecurityYandexCanvaOperaKuaishou TechnologyVercelTelegramxAIVivaldi TechnologiesGoFileLuma AIInVideoNovaLeads
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Malvertising and Supply-Chain Lures Impersonate AI Developer Tools to Deliver Infostealers and RATs | Mallory