The leak was real. The fake GitHub repos that followed were a trap.
On March 31, 2026, Anthropic made a significant mistake. When publishing an update to Claude Code — their terminal-based AI coding agent — they accidentally included a 59.8 MB JavaScript source map file in the npm package. That source map contained the complete, unobfuscated client-side source code: 513,000 lines of TypeScript across 1,906 files. Orchestration logic, permission systems, execution flows, hidden features, build details, security internals — all of it, fully readable, by accident.
The developer community noticed immediately. The code was downloaded rapidly, mirrored across multiple GitHub repositories, and forked thousands of times. For developers curious about how Claude Code works under the hood, this was irresistible. And that curiosity is exactly what hackers counted on.
What the attackers did — and how fast they moved
Within hours of the leak becoming public, threat actors set up fake GitHub repositories claiming to host the leaked Claude Code source. One confirmed malicious repository was published by a user named "idbzoomh" — and it was designed specifically to look legitimate. The repository advertised "unlocked enterprise features" and claimed to remove usage restrictions from Claude Code, which would be appealing to developers who want to use the tool without API limits.
To maximize reach, the attackers optimized the repository for search engines. When developers searched Google for terms like "leaked Claude Code" in the days following the incident, this malicious repository appeared among the top results. Google's algorithm, seeing a GitHub repository with relevant keywords and engagement signals, ranked it high — not knowing it was a trap.
Anyone who downloaded from that repository got a 7-Zip archive. Inside was a file called ClaudeCode_x64.exe — a Rust-based executable. Running it installs two pieces of malware: Vidar infostealer and GhostSocks.
What Vidar does — this is the dangerous part
Vidar is not a simple nuisance. It's a commodity information stealer sold on criminal marketplaces that has been used in thousands of attacks. When it runs on your machine, it systematically harvests:
Browser credentials — every saved username and password in Chrome, Firefox, Edge, and other browsers. That includes your Gmail login, your banking portal, your UPI-linked accounts, your company VPN credentials, and everything else your browser has ever saved.
Credit card data stored in browsers — the card details you've saved for quick checkout on Amazon, Flipkart, Swiggy, or any other site.
Browser cookies and session tokens — these are particularly dangerous because they can let attackers log into your accounts without needing your password. They bypass two-factor authentication in many cases.
Browser history, which reveals what services you use, giving attackers a roadmap for targeted follow-up.
Cryptocurrency wallet files, if present on the machine.
All of this gets packaged up and sent to the attacker's server silently, in the background, while you think you're just looking at leaked source code.
What GhostSocks does — the second payload
GhostSocks is a different kind of malware. It turns your computer into a proxy node — meaning criminals route their internet traffic through your machine. This has two effects: it helps them hide their tracks by making their attacks appear to originate from legitimate-looking IP addresses (yours), and it consumes your bandwidth and computing resources.
From the attacker's perspective, a network of GhostSocks-infected machines is valuable infrastructure for conducting further attacks, scraping websites, credential stuffing campaigns, and more — all using your computer's resources and internet connection, with your IP address taking the apparent blame.
The malicious archive is being updated — more payloads possible
Security researchers who analyzed the malicious repository found that the 7-Zip archive is regularly updated. This means the attackers are actively managing the campaign and could add additional malware payloads at any point. A second GitHub repository with identical code but a different download mechanism was also found — the researchers believe it's the same attacker testing different delivery strategies to see what gets more downloads.
This is an active, ongoing campaign, not a one-time event.
Who is at risk — Indian developers specifically
Claude Code has been popular with Indian developers since launch. India has one of the largest developer communities globally, and AI coding tools have been adopted rapidly. Developers who followed the leak story on Twitter/X, Reddit, or tech Discord servers and went searching for the source code are the primary at-risk group.
If you work in a company environment and your laptop is infected, the risk extends beyond personal credentials. Corporate email access, internal tools, company GitHub repositories, cloud service credentials — all of these can be harvested by Vidar if they were stored in your browser or accessible from your machine.
For Indian freelancers and developers who have international clients — payment processing credentials, client project repositories, communication tool logins — a Vidar infection could create serious professional and financial consequences that go well beyond a personal password change.
How to check if you're affected
If you downloaded anything related to the Claude Code leak from GitHub in the first week of April 2026, assume you may be at risk and take these steps immediately:
Run a full malware scan with a reputable tool — Malwarebytes, Windows Defender, or your corporate endpoint protection. Vidar and GhostSocks should be detected by updated signature databases.
Change your passwords — especially for anything financial. Your banking portals, UPI apps (though UPI PIN itself lives on your phone, your linked email and bank portal credentials are at risk), email accounts, company tools.
Revoke active sessions on critical accounts. Gmail, GitHub, AWS, Azure — every major service has a "sign out of all devices" or "revoke all sessions" option. Use it.
Check your GitHub account for any suspicious activity — unauthorized commits, new SSH keys, OAuth applications you didn't authorize.
If you're on a corporate device, notify your IT security team immediately. The window between infection and credential harvesting is very short with modern infostealers.
The broader lesson — how hackers exploit news events
This attack follows a pattern that security researchers have documented consistently: hackers monitor high-interest tech events and set up traps within hours. A major software leak, a high-profile vulnerability disclosure, a breaking security story — all of these create a pool of curious users who are actively searching for information and more likely to download things without fully verifying them.
Previous versions of this attack have used fake proof-of-concept exploit code, fake security tools, and fake leaked software. The Claude Code leak is just the latest vehicle. The payload changes, but the approach is identical: find something developers want, create a convincing fake, optimize it for search, wait for downloads.
For developers: the only safe source for Claude Code is Anthropic's official npm package (@anthropic-ai/claude-code), installed through the official npm registry. Any third-party repository claiming to host a "better" or "unlocked" version should be treated as suspicious by default.
TamilTech's take
This is a genuinely serious security threat dressed up in a tech curiosity story. The Claude Code leak was interesting — 513,000 lines of Anthropic's AI agent internals is legitimately fascinating for developers. But the moment a major tech event generates search traffic, attackers are ready with optimized fake repositories waiting at the top of Google results. The combination of Vidar infostealer and GhostSocks proxy is a high-value double payload — one steals your credentials immediately, the other turns your machine into criminal infrastructure for the long term. If you downloaded anything claiming to be the leaked Claude Code from any GitHub repository other than Anthropic's official channels, run a full malware scan right now. Don't wait.




Comments (0)
Be the first to comment!