Leak Real — Fake GitHub Repos Trap, Hackers Waiting!
March 31, 2026-ல் Anthropic ஒரு serious mistake பண்ணியது. Claude Code-ஓட npm பேக்கேஜ் அப்டேட்-ல் accidentally 59.8 MB JavaScript source map file include ஆகியது. அந்த file-ல் இருந்தது: complete, unobfuscated source code — 1,906 files-ல் 513,000 lines TypeScript code. Claude Code-ஓட orchestration logic, permissions, execution systems, hidden features, security internals — எல்லாமே fully readable-ஆ leak ஆனது.
Developer community உடனே notice பண்ணியது. Code rapidly download ஆனது, GitHub-ல் thousands of forks ஆனது. Claude Code internally எப்படி work பண்றதுன்னு curious developers-க்கு இது irresistible. அந்த curiosity-தான் hackers-க்கு weapon ஆனது.
Attackers என்ன பண்ணினாங்க?
Leak public ஆன சில மணி நேரத்திலேயே, fake GitHub repositories ready ஆகியிருந்தன. "idbzoomh" என்ற user ஒரு malicious repository publish பண்ணினார் — legitimate-ஆ look ஆகும்படி design பண்ணியது. "Unlocked enterprise features" கொடுக்குது, usage restrictions இல்லை-ன்னு advertise பண்ணினாங்க. Developers-க்கு tempting-ஆ இருக்கும் offer.
Maximum traffic-க்காக repository-ஐ search engine-க்கு optimize பண்ணினாங்க. "leaked Claude Code" Google-ல் search பண்ணினா இந்த malicious repo top results-ல் வந்தது. Google algorithm legitimate-ஆ நினைச்சு rank பண்ணியது — trap என்று தெரியாம.
Download பண்ணினா: 7-Zip archive. Inside: ClaudeCode_x64.exe என்ற Rust-based executable. Run பண்ணினா? Two malware install ஆகும் — Vidar infostealer மற்றும் GhostSocks.
Vidar என்ன பண்றது — இதுதான் Dangerous Part
Vidar என்பது criminal marketplaces-ல் sell ஆகும் commodity information stealer — thousands of attacks-ல் use ஆகியிருக்கு. உங்கள் machine-ல் run ஆகும்போது இவை எல்லாம் திருடுது:
Browser credentials — Chrome, Firefox, Edge-ல் save ஆன every username மற்றும் password. Gmail login, bank portal, UPI-linked accounts, company VPN credentials — எல்லாம். உங்கள் browser save பண்ணிய எல்லாத்தையும்.
Browsers-ல் store ஆன credit card data — Amazon, Flipkart, Swiggy, Zomato-ல் quick checkout-க்கு save பண்ணிய card details.
Browser cookies மற்றும் session tokens — இவை particularly dangerous. Password இல்லாமல் உங்கள் accounts-ல் login பண்ண use பண்ணலாம். Many cases-ல் two-factor authentication bypass ஆகும்.
Browser history — attackers-க்கு உங்கள் services roadmap கிடைக்கும்.
Cryptocurrency wallet files, if present.
இவை எல்லாம் silently attacker-ஓட server-க்கு send ஆகுது — நீங்க source code பாக்குறோம்னு நினைக்கும்போது.
GhostSocks — Second Malware என்ன பண்றது?
GhostSocks different type malware. உங்கள் computer-ஐ proxy node-ஆ turn பண்றது — criminals-ஓட internet traffic உங்கள் machine வழியா route ஆகுது. உங்கள் IP address-ல் இருந்து attacks நடக்கும். Bandwidth consume ஆகும். உங்கள் computer-ஓட resources criminal infrastructure-ஆ use ஆகும்.
Attackers-க்கு GhostSocks-infected machines valuable — further attacks, credential stuffing, website scraping எல்லாத்திற்கும் உங்கள் computer use பண்ணலாம். உங்கள் IP blame ஆகும்.
Active Campaign — Archive Update ஆகுது
Security researchers malicious repository analyze பண்ணும்போது: 7-Zip archive regularly update ஆகுது. Attackers actively campaign manage பண்றாங்க — future iterations-ல் additional malware payloads add ஆகலாம். Identical code-உடன் second GitHub repository-உம் found ஆனது — same attacker different delivery strategies test பண்றது.
இது one-time event இல்லை — ongoing active campaign.
Indian Developers-க்கு Specifically Risk
Claude Code Indian developers-கிட்ட popular tool. India-ல் one of the largest developer communities globally, AI coding tools rapidly adopt ஆகியிருக்கு. Twitter/X, Reddit, tech Discord servers-ல் leak story follow பண்ணி source code search பண்ணிய developers primary at-risk group.
Company environment-ல் laptop இருந்தா risk extends. Corporate email, internal tools, company GitHub repositories, cloud service credentials — Vidar இவை எல்லாத்தையும் harvest பண்ணலாம். International clients-உடன் work பண்றும் Indian freelancers-க்கு — payment credentials, client project repos, communication tool logins — Vidar infection serious professional மற்றும் financial consequences create பண்ணும்.
நீங்கள் Affected-ஆ? இப்படி Check பண்ணுங்க
April 2026 first week-ல் Claude Code leak-related எதையாவது GitHub-ல் இருந்து download பண்ணிருந்தா — immediately இந்த steps எடுங்க:
1. Malware scan run பண்ணுங்க — Malwarebytes, Windows Defender, அல்லது corporate endpoint protection. Vidar மற்றும் GhostSocks updated signature databases-ல் detect ஆகும்.
2. Passwords change பண்ணுங்க — especially financial. Banking portals, email accounts, UPI-linked email (UPI PIN phone-ல் safe, ஆனா linked email credentials risk-ல்), company tools.
3. Critical accounts-ல் active sessions revoke பண்ணுங்க. Gmail, GitHub, AWS, Azure — எல்லாமே "sign out of all devices" option இருக்கு. Use it.
4. GitHub account suspicious activity check பண்ணுங்க — unauthorized commits, new SSH keys, OAuth apps.
5. Corporate device-ல் இருந்தா IT security team-ஐ immediately notify பண்ணுங்க.
Broader Lesson — Hackers News Events Exploit பண்றாங்க
இந்த attack ஒரு consistent pattern follow பண்றது: hackers high-interest tech events monitor பண்ணி hours-ல் traps setup பண்றாங்க. Major software leak, high-profile vulnerability, breaking security story — இவை curious users create பண்றது, அவங்க actively search பண்றாங்க, verify பண்ணாம download பண்ண ready-ஆ இருக்காங்க.
Previous attacks fake proof-of-concept exploit code, fake security tools, fake leaked software use பண்ணினது. Claude Code leak latest vehicle. Payload changes, approach identical: developers want பண்றதை find பண்ணுங்க, convincing fake create பண்ணுங்க, search optimize பண்ணுங்க, downloads-க்கு wait பண்ணுங்க.
Claude Code-ஓட safe source: Anthropic-ஓட official npm package மட்டும். Terminal-ல்:
npm install -g @anthropic-ai/claude-codeOfficial npm registry மட்டும். "Unlocked" அல்லது "better" version claim பண்றும் எந்த third-party GitHub repository-யும் avoid பண்ணுங்க.
TamilTech-ஓட கருத்து
Claude Code leak genuinely interesting-ஆ இருந்தது — 513,000 lines Anthropic AI agent internals developers-க்கு fascinating. ஆனா major tech event search traffic generate பண்ணும்போது, attackers Google top results-ல் optimized fake repositories-உடன் ready-ஆ இருக்காங்க. Vidar infostealer மற்றும் GhostSocks proxy combination high-value double payload — ஒண்ணு immediately credentials steal பண்றது, மற்றொண்ணு long-term criminal infrastructure-ஆ machine-ஐ use பண்றது. Official channel-க்கு வெளியே GitHub-ல் இருந்து Claude Code-related எதையாவது download பண்ணிருந்தா — இப்பவே malware scan run பண்ணுங்க. Wait வேண்டாம்.




கருத்துகள் (0)
Be the first to comment!