April 2, 2026via The Register AI/ML
They thought they were downloading Claude Code source. They got a nasty dose of malware instead
Why it matters
This security incident highlights the growing risks of AI-related social engineering attacks targeting developers and could impact trust in open-source AI development practices.
Key signals
- Attackers used fake Claude source code as bait
- Malware distributed through GitHub repositories
- Targets were AI developers seeking Claude's codebase
The hook
Fake Claude source code on GitHub just delivered malware to dozens of AI developers.
Relevance score:85/100