Curiosity Trap — Developer-களை Target பண்றும் Smart Attack
ஒரு major AI company-ஓட source code accidentally leak ஆனா, developers curious ஆவது natural. எப்படி build பண்ணியிருக்காங்க, architecture என்னன்னு பாக்கணும்னு feel ஆகும். GitHub-ல் search பண்ணுவீங்க, ஒரு repository கிடைக்கும், clone பண்ணுவீங்க, run பண்ணுவீங்க.
Hackers exactly இதையே expect பண்ணினாங்க.
March 31, 2026-ல் Anthropic accidentally approximately 5,13,000 lines of unobfuscated TypeScript source code-ஐ expose பண்ணியது — Claude Code-ஓட (AI coding tool) — public npm package-ல் bundle ஆன JavaScript source map file மூலம். Security researcher flag பண்ணிய hours-ல், GitHub-ல் repositories flood ஆகியது — leaked source host பண்றோம்ன்னு claim பண்றது. பெரும்பாலும் genuine reposts. சிலது இல்லை.
Cybersecurity researchers discover பண்ணினாங்க: அந்த repositories wave-ல் certain GitHub accounts Vidar infostealer malware மற்றும் Ghostsocks proxy malware-ஐ Claude Code source files-ஆ appear ஆகும் files-ல் embed பண்ணியிருக்காங்க. இந்த malicious repos Claude Code leak பத்தி search queries-க்கு well rank ஆகும்படி optimize பண்ணியிருந்தது — யாரும் GitHub-ல் leaked source search பண்ணினா poisoned repository-ல் land ஆகும் real chance இருந்தது.
என்ன Leak ஆனது — Developers ஏன் Care பண்ணினாங்க?
Claude Code என்பது Anthropic-ஓட terminal-based AI coding agent. Simple chatbot wrapper இல்லை — உங்கள் codebase read பண்ணி, multiple files-ல் context understand பண்ணி, code write பண்ணி, commands run பண்ணி, multi-step programming tasks-ல் semi-autonomously operate பண்ணும் tool. Indian developers freelance work, startup projects, enterprise development workflows-க்கு increasingly adopt பண்றாங்க.
Leaked material: client-side TypeScript source code — approximately 5,13,000 lines. Claude Code-ஓட source ever public ஆனதில்லை. Leak யாரும் பார்த்தா unusually detailed view கிடைக்கும்: context எப்படி manage பண்றது, file system operations எப்படி handle பண்றது, agent loops எப்படி structure பண்றது, என்ன APIs call பண்றது, users-ஐ எப்படி authenticate பண்றது.
Claude Code professionally use பண்றும் developers-க்கு genuinely interesting information. AI agent architecture study பண்றவங்களுக்கு valuable. Legitimate interest real-ஆ இருந்தது — exactly அதனால்தான் malware trap effective-ஆ இருந்தது.
Vidar மற்றும் Ghostsocks — என்ன Damage பண்றது?
Fake repositories-ல் embed ஆன two malware families specifically understand பண்றது important — repository delete பண்ணிட்ட பிறகும் lasting damage cause பண்ண designed.
Vidar என்பது ஒரு infostealer — credentials, session tokens, cryptocurrency wallet files, browser-saved passwords extract பண்றதற்காக specifically designed malware. Vidar உங்கள் system-ல் run ஆனா: Chrome, Firefox, Edge-ல் saved passwords harvest பண்ணும்; attackers-கு உங்கள் password தேவையில்லாம accounts-ல் log in பண்ண முடியும்படி cookies மற்றும் session tokens extract பண்ணும்; cryptocurrency wallet files மற்றும் seed phrases தேடும்; எல்லாத்தையும் attacker-ஓட server-க்கு silently, quickly send பண்ணும் — often minutes-ல்.
Indian developers-க்கு Vidar risk specific-ஆ serious: banking apps, UPI apps, GitHub account, AWS அல்லது Google Cloud credentials, freelance platform accounts-ஓட saved passwords browser-ல் இருந்தா, Vidar எல்லாத்தையும் harvest பண்ணலாம். Upwork, Toptal, அல்லது Fiverr-ல் Indian freelancers-கு client credentials அல்லது payment information browser-ல் store பண்ணியிருந்தா particular risk. Razorpay, Cashfree, அல்லது Stripe API keys environment files அல்லது browser-saved passwords-ல் வச்சிருக்கும் developers-க்கு potential financial exposure.
Ghostsocks different kind of threat. உங்கள் infected computer-ஐ ஒரு proxy node-ஆக turn பண்றது — attackers-ஓட own traffic உங்கள் machine-ல் இருந்து route ஆகும். Fraud operations-க்கு, cyberattacks-ஓட origin mask பண்ண, அல்லது geo-restricted services access பண்ண use ஆகும். Practical result: உங்கள் IP address நீங்கள் செய்யாத criminal activity-க்காக flag ஆகும். Internet service providers மற்றும் platforms உங்கள் connection block அல்லது report பண்ணலாம்.
Cleanup Scale — இன்னும் Over இல்லை
Anthropic-ஓட response aggressive ஆனாலும் imperfect. Company initially 8,000-க்கும் மேற்பட்ட GitHub repositories-ஐ target பண்ணி copyright takedown notices file பண்ணியது — leaked code hosting பண்றதற்காக. GitHub-ஓட DMCA takedown process copyright infringement handle பண்றதற்கு designed — security emergency-க்கு இல்லை. Removal process time எடுத்தது.
Anthropic later takedown scope-ஐ 96 repositories-க்கு narrow பண்ணியது — leaked code directly reproduce பண்ணும் copies மற்றும் adaptations. 8,000-repository initial sweep apparently too broad — leaked code reference அல்லது discuss பண்ண legitimate reasons உள்ள repositories-ஐயும் include பண்ணியிருந்தது.
Problem என்னன்னா இந்த narrowing many repositories still accessible-ஆ வைக்குது. Malware embed பண்ணிய fake repos specifically legitimate-ஆ look ஆகும்படி crafted — proper README files, reasonable commit histories, search-optimized descriptions. Automated DMCA processes-ல் identify பண்றது harder.
Early April 2026-ல் situation still active. New repositories continue to appear. April-ஓட first week-ல் GitHub-ல் Claude Code source search பண்ணி anything download பண்ணியிருந்தா — thorough security scan run பண்ணும் வரை machine potentially compromised-ஆ treat பண்ணணும்.
Indian Developers-க்கு இப்போவே என்ன பண்ணணும்?
Claude Code source code-க்காக GitHub-ல் search பண்ணி, எந்த repository-யாவது clone பண்ணி, அல்லது unofficial Claude Code repository-ல் இருந்து code run பண்ணியிருந்தா — இப்போவே இந்த steps எடுங்க.
முதலில், full malware scan run பண்ணுங்க. Windows-ல் updated definitions-உடன் Windows Defender Vidar variants catch பண்ணும். macOS-ல் Malwarebytes free version effective. Quick scan rely பண்ணாதீங்க — development folders மற்றும் npm cache including எல்லா directories-யும் check பண்றும் full system scan run பண்ணுங்க.
அடுத்து, browser-ல் stored credentials உள்ள accounts passwords change பண்ணுங்க. High-value accounts-ல் start பண்ணுங்க: GitHub, GitLab, AWS, Google Cloud, Azure, cloud hosting providers, banking apps, UPI-linked accounts, freelance platform accounts. Password manager use பண்ணுங்க, existing ones reuse பண்ணாதீங்க.
மூன்றாவது, infected machine-ல் store ஆன எந்த API keys-யும் revoke மற்றும் regenerate பண்ணுங்க — environment files-ல், project directories-ல் .env files-ல், அல்லது IDE configuration files-ல். AWS, Google Cloud, Razorpay, Stripe, OpenAI, Anthropic — அந்த machine-ல் இருந்த எந்த API key-யும் compromised-ஆ consider பண்ணுங்க.
நான்காவது, critical accounts-ல் active sessions check பண்ணுங்க. GitHub, Google, பெரும்பாலான cloud providers எல்லா active sessions பாக்கவும் recognize பண்ணாதவற்றை revoke பண்ணவும் let பண்றது. Vidar specifically session cookies harvest பண்றது — password change பண்ணிட்ட பிறகும் access maintain பண்ண enable ஆகும்.
ஐந்தாவது, உங்கள் IP address flag ஆகியிருக்கான்னு check பண்ணுங்க. AbuseIPDB போன்ற services உங்கள் IP malicious activity-க்காக report ஆகியிருக்கான்னு look up பண்ண allow பண்றது. Ghostsocks உங்கள் machine proxy-ஆ use பண்ணியிருந்தா, ISP-கிட்ட address பண்ண வேண்டிய reports accumulate ஆகியிருக்கலாம்.
TamilTech-ஓட கருத்து
Claude Code malware campaign — developers-ஐ target பண்றும் supply chain social engineering-ஓட textbook example. Technical curiosity attack surface ஆகுது. Lesson: "leaked code பத்தி curious ஆகாதீங்க" இல்லை — AI space-ல் high-profile leak அல்லது controversial release வரும்போதெல்லாம், GitHub hours-ல் minefield ஆகிவிடும். Unofficial AI tool repository-ஐ unsolicited email attachment-ஐ மாதிரி treat பண்ணுங்க. Cloud credentials, API keys, freelance platform accounts development machine-ல் உள்ள Indian developers-க்கு Vidar infection cost just reformatted hard drive இல்லை — potential financial loss, compromised client data, weeks of credential rotation. இதுக்கு extra caution worth.




கருத்துகள் (0)
Be the first to comment!