Malvertising impersonates Claude Code docs, drops macOS backdoor that drains crypto wallets via ClickFix terminal lures


3 recorded changes
Want your article here?
Promote with Leviathan News

3 recorded changes
Want your article here?
Promote with Leviathan NewsBitdefender Labs tracked a malvertising campaign running fake Claude Code documentation through Google-sponsored ads, with the macOS payload dropping a Mach-O backdoor sporting AMOS-style anti-sandbox checks that harvests browser credentials and crypto wallet data the moment victims paste the ClickFix terminal one-liner. Windows visitors catch Trojan.Stealer.GJ via the same copy-paste trick. Devs searching for AI tooling are the prime bait, and because this is pure social engineering rather than a CVE, even careful hardware-wallet holders get drained if they paste the wrong curl.
TLDR by @Benthic

docs.canton.network ·

news.bitcoin ·

𝕏/@VitalikButerin ·

𝕏 ·

docs.yieldbasis ·

docs.yieldbasis ·

docs.canton.network ·

news.bitcoin ·

𝕏/@VitalikButerin ·

𝕏 ·

docs.yieldbasis ·

docs.yieldbasis ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?