‹ முகப்புக்கு திரும்ப

Urgent Security Alert: Claude Code Leak-ஐ Use பண்ணி Hackers Developers-ஓட Passwords திருடுறாங்க — GitHub-ல் Fake Repos!

March 31-ல் Anthropic-ஓட Claude Code source code accidentally leak ஆனது. Hackers உடனே fake GitHub repositories create பண்ணி malware spread பண்றாங்க. 'leaked Claude Code' Google-ல் search பண்ணி download பண்ணீங்களா? உங்கள் passwords, credit cards எல்லாம் திருடப்பட்டிருக்கலாம். இப்பவே action எடுங்க.

Keerthika 3 min read
Google-ல் Follow
அப்டேட் 5 மாதங்கள் முன்
Security Urgent Security Alert: Claude Code Leak-ஐ Use பண்ணி Hackers Developers-ஓட Passwords திருடுறாங்க — GitHub-ல் Fake Repos! 3 நிமிடம் மீதம் Google-ல் Follow
Urgent Security Alert: Claude Code Leak-ஐ Use பண்ணி Hackers Developers-ஓட Passwords திருடுறாங்க — GitHub-ல் Fake Repos!

தமிழ்டெக் AI சுருக்கம்

Anthropic March 2026-ல Claude Code-ஓட npm update-ல source map file accidentally include ஆகி, full unobfuscated TypeScript source code leak ஆயிடுச்சு — orchestration, permissions, security internals எல்லாம் வெளியே தெரிஞ்சது. அந்த curiosity-ஐ use பண்ணி hackers fake GitHub repos போட்டு “unlocked enterprise features”ன்னு advertise பண்ணி, download பண்ணா Vidar infostealerயும் GhostSocks malwareயும் install ஆகும்படி trap வச்சாங்க. Vidar browser passwords, saved cards, cookies, session tokens, crypto wallet files எல்லாம் திருடி attacker server-க்கு அனுப்பும்; GhostSocks உங்க PC-ஐ proxy node-ஆ மாத்தி criminal traffic route பண்ணும். Indian developers Claude Code ரொம்ப use பண்றதால company laptops, freelancers-ஓட client credentials எல்லாம் risk-ல இருக்கு — April first week-ல leak-related ஏதாவது GitHub-ல இருந்து download பண்ணிருந்தா உடனே malware scan ஓட்டுங்க, passwords change பண்ணுங்க, critical accounts-ல sessions revoke பண்ணுங்க. Safe source Anthropic-ஓட official npm package மட்டும் (`@anthropic-ai/claude-code`); “leaked” அல்லது “unlocked”ன்னு சொல்லி வர third-party GitHub repo-ஐ avoid பண்ணுங்க.

  • Anthropic March 31-ல் 513,000 lines Claude Code source leak — hackers உடனே Google top results-ல் fake GitHub repos create பண்ணி Vidar malware spread பண்றாங்க
  • Vidar browser-ல் save ஆன passwords, credit cards, session cookies எல்லாம் steal பண்றது — GhostSocks உங்கள் PC-ஐ criminal proxy-ஆ turn பண்றது
  • ClaudeCode_x64.exe download பண்ணிருந்தா: உடனே malware scan, passwords change, all sessions revoke பண்ணுங்க — active campaign, archive regularly update ஆகுது

AI உதவியுடன் தயாரான சுருக்கம் — தமிழ்டெக் எடிட்டர்ஸ் சரிபார்த்தது.

0:00
0:00
🔒 Listen வசதி subscribers-க்கு மட்டும். Subscribe செய்யுங்கள்

Leak Real — Fake GitHub Repos Trap, Hackers Waiting!

March 31, 2026-ல் Anthropic ஒரு serious mistake பண்ணியது. Claude Code-ஓட npm பேக்கேஜ் அப்டேட்-ல் accidentally 59.8 MB JavaScript source map file include ஆகியது. அந்த file-ல் இருந்தது: complete, unobfuscated source code — 1,906 files-ல் 513,000 lines TypeScript code. Claude Code-ஓட orchestration logic, permissions, execution systems, hidden features, security internals — எல்லாமே fully readable-ஆ leak ஆனது.

Developer community உடனே notice பண்ணியது. Code rapidly download ஆனது, GitHub-ல் thousands of forks ஆனது. Claude Code internally எப்படி work பண்றதுன்னு curious developers-க்கு இது irresistible. அந்த curiosity-தான் hackers-க்கு weapon ஆனது.

Attackers என்ன பண்ணினாங்க?

Leak public ஆன சில மணி நேரத்திலேயே, fake GitHub repositories ready ஆகியிருந்தன. "idbzoomh" என்ற user ஒரு malicious repository publish பண்ணினார் — legitimate-ஆ look ஆகும்படி design பண்ணியது. "Unlocked enterprise features" கொடுக்குது, usage restrictions இல்லை-ன்னு advertise பண்ணினாங்க. Developers-க்கு tempting-ஆ இருக்கும் offer.

Maximum traffic-க்காக repository-ஐ search engine-க்கு optimize பண்ணினாங்க. "leaked Claude Code" Google-ல் search பண்ணினா இந்த malicious repo top results-ல் வந்தது. Google algorithm legitimate-ஆ நினைச்சு rank பண்ணியது — trap என்று தெரியாம.

Download பண்ணினா: 7-Zip archive. Inside: ClaudeCode_x64.exe என்ற Rust-based executable. Run பண்ணினா? Two malware install ஆகும் — Vidar infostealer மற்றும் GhostSocks.

Vidar என்ன பண்றது — இதுதான் Dangerous Part

Vidar என்பது criminal marketplaces-ல் sell ஆகும் commodity information stealer — thousands of attacks-ல் use ஆகியிருக்கு. உங்கள் machine-ல் run ஆகும்போது இவை எல்லாம் திருடுது:

Browser credentials — Chrome, Firefox, Edge-ல் save ஆன every username மற்றும் password. Gmail login, bank portal, UPI-linked accounts, company VPN credentials — எல்லாம். உங்கள் browser save பண்ணிய எல்லாத்தையும்.

Browsers-ல் store ஆன credit card data — Amazon, Flipkart, Swiggy, Zomato-ல் quick checkout-க்கு save பண்ணிய card details.

Browser cookies மற்றும் session tokens — இவை particularly dangerous. Password இல்லாமல் உங்கள் accounts-ல் login பண்ண use பண்ணலாம். Many cases-ல் two-factor authentication bypass ஆகும்.

Browser history — attackers-க்கு உங்கள் services roadmap கிடைக்கும்.

Cryptocurrency wallet files, if present.

இவை எல்லாம் silently attacker-ஓட server-க்கு send ஆகுது — நீங்க source code பாக்குறோம்னு நினைக்கும்போது.

GhostSocks — Second Malware என்ன பண்றது?

GhostSocks different type malware. உங்கள் computer-ஐ proxy node-ஆ turn பண்றது — criminals-ஓட internet traffic உங்கள் machine வழியா route ஆகுது. உங்கள் IP address-ல் இருந்து attacks நடக்கும். Bandwidth consume ஆகும். உங்கள் computer-ஓட resources criminal infrastructure-ஆ use ஆகும்.

Attackers-க்கு GhostSocks-infected machines valuable — further attacks, credential stuffing, website scraping எல்லாத்திற்கும் உங்கள் computer use பண்ணலாம். உங்கள் IP blame ஆகும்.

Active Campaign — Archive Update ஆகுது

Security researchers malicious repository analyze பண்ணும்போது: 7-Zip archive regularly update ஆகுது. Attackers actively campaign manage பண்றாங்க — future iterations-ல் additional malware payloads add ஆகலாம். Identical code-உடன் second GitHub repository-உம் found ஆனது — same attacker different delivery strategies test பண்றது.

இது one-time event இல்லை — ongoing active campaign.

Indian Developers-க்கு Specifically Risk

Claude Code Indian developers-கிட்ட popular tool. India-ல் one of the largest developer communities globally, AI coding tools rapidly adopt ஆகியிருக்கு. Twitter/X, Reddit, tech Discord servers-ல் leak story follow பண்ணி source code search பண்ணிய developers primary at-risk group.

Company environment-ல் laptop இருந்தா risk extends. Corporate email, internal tools, company GitHub repositories, cloud service credentials — Vidar இவை எல்லாத்தையும் harvest பண்ணலாம். International clients-உடன் work பண்றும் Indian freelancers-க்கு — payment credentials, client project repos, communication tool logins — Vidar infection serious professional மற்றும் financial consequences create பண்ணும்.

நீங்கள் Affected-ஆ? இப்படி Check பண்ணுங்க

April 2026 first week-ல் Claude Code leak-related எதையாவது GitHub-ல் இருந்து download பண்ணிருந்தா — immediately இந்த steps எடுங்க:

1. Malware scan run பண்ணுங்க — Malwarebytes, Windows Defender, அல்லது corporate endpoint protection. Vidar மற்றும் GhostSocks updated signature databases-ல் detect ஆகும்.

2. Passwords change பண்ணுங்க — especially financial. Banking portals, email accounts, UPI-linked email (UPI PIN phone-ல் safe, ஆனா linked email credentials risk-ல்), company tools.

3. Critical accounts-ல் active sessions revoke பண்ணுங்க. Gmail, GitHub, AWS, Azure — எல்லாமே "sign out of all devices" option இருக்கு. Use it.

4. GitHub account suspicious activity check பண்ணுங்க — unauthorized commits, new SSH keys, OAuth apps.

5. Corporate device-ல் இருந்தா IT security team-ஐ immediately notify பண்ணுங்க.

Broader Lesson — Hackers News Events Exploit பண்றாங்க

இந்த attack ஒரு consistent pattern follow பண்றது: hackers high-interest tech events monitor பண்ணி hours-ல் traps setup பண்றாங்க. Major software leak, high-profile vulnerability, breaking security story — இவை curious users create பண்றது, அவங்க actively search பண்றாங்க, verify பண்ணாம download பண்ண ready-ஆ இருக்காங்க.

Previous attacks fake proof-of-concept exploit code, fake security tools, fake leaked software use பண்ணினது. Claude Code leak latest vehicle. Payload changes, approach identical: developers want பண்றதை find பண்ணுங்க, convincing fake create பண்ணுங்க, search optimize பண்ணுங்க, downloads-க்கு wait பண்ணுங்க.

Claude Code-ஓட safe source: Anthropic-ஓட official npm package மட்டும். Terminal-ல்:

npm install -g @anthropic-ai/claude-code

Official npm registry மட்டும். "Unlocked" அல்லது "better" version claim பண்றும் எந்த third-party GitHub repository-யும் avoid பண்ணுங்க.

TamilTech-ஓட கருத்து

Claude Code leak genuinely interesting-ஆ இருந்தது — 513,000 lines Anthropic AI agent internals developers-க்கு fascinating. ஆனா major tech event search traffic generate பண்ணும்போது, attackers Google top results-ல் optimized fake repositories-உடன் ready-ஆ இருக்காங்க. Vidar infostealer மற்றும் GhostSocks proxy combination high-value double payload — ஒண்ணு immediately credentials steal பண்றது, மற்றொண்ணு long-term criminal infrastructure-ஆ machine-ஐ use பண்றது. Official channel-க்கு வெளியே GitHub-ல் இருந்து Claude Code-related எதையாவது download பண்ணிருந்தா — இப்பவே malware scan run பண்ணுங்க. Wait வேண்டாம்.

நாளைய டெக் செய்திகள் உங்க WhatsApp-க்கே

தினமும் ஒரு சின்ன update, இலவசம். TamilTech channel-ஐ follow பண்ணுங்க.

What do you think?

people reacted

Keerthika

தமிழ்டெக் எடிட்டோரியல் டீம் · 3,346 கட்டுரைகள்

Keerthika is an editor at TamilTech, the Tamil and English technology publication founded by Praveen Kumar S. She covers AI, smartphones, gadgets, EVs, startups and cybersecurity i...

மேலும் Keerthika

WhatsApp-ல் TamilTech-ஐக் கேளுங்க

டெக் சந்தேகமா? தமிழிலோ ஆங்கிலத்திலோ கேளுங்க — எங்க WhatsApp அசிஸ்டன்ட் TamilTech கட்டுரைகளில் இருந்து சில நொடிகளில் பதில் சொல்லும்.

தொடர்புடைய செய்திகள்

கருத்துகள் (0)

| Supports **bold**, *italic*, `code`

Be the first to comment!

அடுத்த செய்தி PixelLeak: AI Coding Agents 13,000 கம்பெனி Screenshots-ஐ GitHub-ல Public ஆக்கிடுச்சு
Tamiltech

Tamiltech

Install app for faster access

Earn XP 🏆
WhatsApp
Notifications