The curiosity trap: why this malware attack is particularly dangerous for developers
When a major AI company accidentally leaks its source code, developers get curious. That's completely natural. You want to see how it works, what's under the hood, whether there are interesting architectural decisions you can learn from. So you search GitHub for the leaked code, find a repository, clone it, and run it.
That's exactly what hackers were counting on.
On March 31, 2026, Anthropic accidentally exposed approximately 513,000 lines of unobfuscated TypeScript source code for Claude Code — its AI coding tool — through a JavaScript source map file that was bundled into a public npm package. Within hours of the leak being flagged by a security researcher, GitHub was flooded with repositories claiming to host the leaked source. Most were genuine reposts. Some were not.
Cybersecurity researchers discovered that certain GitHub accounts in that wave of repositories had embedded Vidar infostealer malware and Ghostsocks proxy malware into what appeared to be Claude Code source files. These malicious repos were optimized to rank well in search results for queries about the Claude Code leak, which means anyone searching for the leaked source on GitHub had a real chance of landing on a poisoned repository.
What exactly got leaked — and why developers cared
Claude Code is Anthropic's terminal-based AI coding agent. It's not a simple chatbot wrapper — it's a tool that can read your codebase, understand context across files, write code, run commands, and operate semi-autonomously on multi-step programming tasks. Indian developers have been increasingly adopting it for freelance work, startup projects, and enterprise development workflows.
The leaked material was the client-side TypeScript source code — approximately 513,000 lines. This is significant because Claude Code's source had never been public. The leak gave anyone who saw it an unusually detailed view of how Anthropic built the tool: how it manages context, how it handles file system operations, how it structures agent loops, what APIs it calls, and how it authenticates users.
For developers who use Claude Code professionally, this was genuinely interesting information. For developers thinking about building competing tools or studying AI agent architecture, it was valuable. The legitimate interest was real — which is exactly what made the malware trap effective.
Vidar and Ghostsocks — what these malware strains actually do
The two malware families embedded in the fake repositories are worth understanding specifically, because their capabilities are designed to cause lasting damage even after you've deleted the repository.
Vidar is an infostealer — a category of malware specifically designed to extract credentials, session tokens, cryptocurrency wallet files, and browser-saved passwords from an infected machine. Once Vidar runs on your system, it harvests saved passwords from Chrome, Firefox, and Edge; it extracts cookies and session tokens that can let attackers log into your accounts without needing your password; it looks for cryptocurrency wallet files and seed phrases; and it sends everything it finds to the attacker's server. The entire process happens silently and quickly, often within minutes of execution.
For Indian developers, the specific Vidar risk is serious: if you have saved passwords for your banking apps, UPI apps, GitHub account, AWS or Google Cloud credentials, or freelance platform accounts in your browser, Vidar can harvest all of it. Indian freelancers on Upwork, Toptal, or Fiverr who store client credentials or payment information in browsers are at particular risk. Developers with Razorpay, Cashfree, or Stripe API keys stored in environment files or browser-saved passwords face potential financial exposure.
Ghostsocks is a different kind of threat. It turns your infected computer into a proxy node — meaning your internet connection gets used by attackers to route their own traffic through your machine. This is used for fraud operations, to mask the origin of cyberattacks, or to access geo-restricted services. The practical result: your IP address gets flagged for criminal activity you didn't conduct. Internet service providers and platforms may block or report your connection. If the attackers use your machine as a proxy for something serious, you could face legal complications.
The scale of the cleanup — and why it's still not over
Anthropic's response to the leak has been aggressive but imperfect. The company initially filed copyright takedown notices targeting more than 8,000 GitHub repositories that were hosting copies of the leaked code. GitHub's DMCA takedown process is designed to handle copyright infringement, not security emergencies, so the removal process took time.
Anthropic later narrowed its takedown scope to 96 repositories — copies and adaptations that most directly reproduced the leaked code. The 8,000-repository initial sweep was apparently too broad and included repositories that had legitimate reasons to reference or discuss the code without reproducing it wholesale.
The problem with this narrowing is that it leaves many repositories still accessible, and cybersecurity researchers have noted that malicious repositories specifically designed to look legitimate are harder to identify through automated DMCA processes than straightforward copies. The fake repos with malware were crafted to appear plausible — they had proper-looking README files, reasonable commit histories, and search-optimized descriptions.
As of early April 2026, the situation is still active. New repositories continue to appear, some legitimate, some not. If you searched GitHub for Claude Code source in the first week of April and downloaded anything, you should treat your machine as potentially compromised until you've run a thorough security scan.
This isn't the first time Claude Code was used as malware bait
This attack follows an earlier campaign that exploited interest in Claude Code for the same purpose. Claude Code requires developer-level technical familiarity to set up — it's not a consumer app with a simple installer. Hackers recognized that the kind of developer who searches for Claude Code setup guides or leaked versions is likely to have valuable credentials: cloud provider API keys, development platform accounts, client codebases, and financial accounts linked to freelancing work.
The pattern is becoming recognizable: whenever a high-profile AI tool generates significant developer interest — whether through a new release, a controversy, or a leak — malicious repositories appear on GitHub within hours, SEO-optimized to catch curious developers. This happened with Cursor AI setup files, with various GPT wrapper tools, and now twice with Claude Code.
What Indian developers specifically need to do right now
If you searched GitHub for Claude Code source code, cloned any repository, or ran any code from an unofficial Claude Code repository in the past two weeks, take these steps immediately.
First, run a full malware scan using a reputable security tool. Windows Defender with updated definitions will catch Vidar variants. On macOS, Malwarebytes free version is effective. Don't rely on a quick scan — run a full system scan that checks all directories including your development folders and npm cache.
Second, change your passwords for any account whose credentials are stored in your browser. Start with the highest-value accounts: GitHub, GitLab, AWS, Google Cloud, Azure, any cloud hosting provider, your banking apps, UPI-linked accounts, and freelance platform accounts. Use a password manager and generate new passwords rather than reusing existing ones.
Third, revoke and regenerate any API keys that were stored on the infected machine — in environment files, in .env files in project directories, or in IDE configuration files. AWS, Google Cloud, Razorpay, Stripe, OpenAI, Anthropic — any API key that was on that machine should be considered compromised.
Fourth, check your active sessions on critical accounts. GitHub, Google, and most cloud providers let you see all active sessions and revoke ones you don't recognize. Do this for every important account, because Vidar specifically harvests session cookies that can maintain access even after a password change.
Fifth, check whether your IP address has been flagged. Services like AbuseIPDB let you look up whether your IP has been reported for malicious activity. If Ghostsocks used your machine as a proxy, your IP may have accumulated reports you'll need to address with your ISP.
TamilTech's take
The Claude Code malware campaign is a textbook example of supply chain social engineering targeted at developers — people who should know better but get caught precisely because their technical curiosity is an attack surface. The lesson isn't "don't be curious about leaked code" (though downloading leaked proprietary code raises its own ethical questions). The lesson is that whenever there's a high-profile leak or controversial release in the AI space, GitHub becomes a minefield within hours. Treat any unofficial repository of a major AI tool with the same suspicion you'd give an unsolicited email attachment. If you're an Indian developer who uses cloud credentials, API keys, or freelance platform accounts on your development machine, the cost of getting Vidar-infected is not just a reformatted hard drive — it's potential financial loss, compromised client data, and weeks of credential rotation. That's worth the extra caution.




Comments (0)
Be the first to comment!