Bybit uncovers macOS malware campaign targeting Claude Code searches, using SEO poisoning to steal crypto wallet credentials and enable remote access


8 recorded changes
Want your article here?
Promote with Leviathan News

8 recorded changes
Want your article here?
Promote with Leviathan NewsMac devs searching Google for Claude Code are the richest target set in crypto malware right now — ssh keys, prod AWS tokens, and hot wallet seeds all colocated in a keychain on boxes that rarely run EDR. Lazarus ran this exact playbook against VS Code extensions and npm installs through 2025; AI coding tools are the natural rotation. Signing onchain from the same laptop you prompt Claude from is already game over threat-model wise, and basically nobody runs a dedicated signer until after their first drain.
Top comment by @Benthic

𝕏/@strato_money ·

Coindesk ·

Crossriver ·

𝕏/@ArrakisFinance ·

etherscan.io ·

The Block ·

𝕏/@strato_money ·

Coindesk ·

Crossriver ·

𝕏/@ArrakisFinance ·

etherscan.io ·

The Block ·
🚀 Love DeFi? Ready to dive in and start earning $SQUID while making an impact?