Threats & Adversaries · Credential Theft

Fake Claude Code Pages Turn Install Text Into Theft

The browser is the attack surface here, not the download URL. A developer can see a normal-looking Claude Code install page, copy the command, and still pull a stealer from an attacker domain because the page text is altered while the fetched PowerShell file looks clean.

Ontinue tied the campaign to three operator-controlled domains registered in April 2026 and a lure pushed through sponsored search results for "install claude code." The payload targets Chromium-based browsers, including Chrome, Edge, Brave, Vivaldi, Perplexity Comet, and Arc, and steals cookies, passwords, and payment data from developer workstations.

This pattern defeats fetch-based scanning and turns search-driven install workflows into credential theft. The risk persists anywhere developers copy commands from documentation pages without verifying that the displayed command and the downloaded script point to the same place.

2 sources · May 12

Timeline

Sources

Vendor digest: Microsoft

Part of the PlainSec briefing for 2026-05-12

Every edition of this story: Fake Claude Code Pages Turn Install Text Into Theft

More from today