Platforms Enterprise It SecurityControl

Claude Code source code exposure and trojanized GitHub releases

April 3, 2026Gray Hats, Tanya Janca | Shehackspurple, Cyber_OSINT

Trend Micro Research and others describe a packaging mistake that exposed internal Claude Code source files, followed by threat actors luring users into downloading trojanized GitHub Release archives, reinforcing how AI tooling leaks can become supply chain bait.

Anthropic strikes back after the Claude Code leak, nuking 8,100 GitHub repos.
Anthropic employee error exposes Claude Code source
Anthropic’s Claude Code leak led to widespread public replication and threat actor activity, with trojanized forks, malicious payloads (Vidar/GhostSocks), and intensified phishing through GitHub repositories and social-engineering lures.
Claude Code leak used to push infostealer malware on GitHub
⚠️ WARNING - Attackers are weaponizing the Claude Code leak.
Fake GitHub repos now deploy Vidar Stealer and GhostSocks, using trojanized builds that look legitimate.
They thought they were downloading Claude Code source. They got a nasty dose of malware instead
WARNING - Attackers are weaponizing the Claude Code leak.
Anthropic strikes 8,100+ GitHub repositories with a massive DMCA claim to purge leaked "Claude Code."
Discover how the AI giant is scrubbing its IP from the web.
The leaked Claude Code source made it work with any LLM model: GPT, DeepSeek, Gemini, Llama, MiniMax. Open source.
Everyone arguing about the Claude Code leak.
Got a message today: "It looks like a few of your recent prompts don’t meet our Usage Policy."
claude seems nerfed for the last 3 days.
A packaging mistake exposed internal Claude Code source files.
Threat actors rapidly used the publicity to lure users into downloading trojanized GitHub Release archives.
Leak: Claude code exposure
Which is hilarious because that’s exactly what Claude leaked
Gray Hats
Tanya Janca | Shehackspurple
Cyber_OSINT
Blue Team News
The Cyber Security Hub™
BleepingComputer
The Hacker News
Kimberly
Nicolas Krassas
Md Ismail Šojal
payloadartist
s1r1us
Trend Micro Research
BowTiedCyber | Evan Lutz
claude codesupply chaintrojanized releasesclaudegithubsupply chainclaude codeopen sourcesource codedata leakmalware analysis

See what authorities are saying right now

This finding is one of many signals tracked across Cyber Security. The live feed updates every few hours with new authority voices, debates, and emerging ideas.

← Back to Cyber Security