Fake Claude Code Pages Turn Install Text Into Theft

The browser is the attack surface here, not the download URL. A developer can see a normal-looking Claude Code install page, copy the command, and still pull a stealer from an attacker domain because the page text is altered while the fetched PowerShell file looks clean. Ontinue tied the campaign to three operator-controlled domains registered in April 2026 and a lure pushed through sponsored search results for "install claude code." The payload targets Chromium-based browsers, including Chrome, Edge, Brave, Vivaldi, Perplexity Comet, and Arc, and steals cookies, passwords, and payment data from developer workstations. This pattern defeats fetch-based scanning and turns search-driven install workflows into credential theft. The risk persists anywhere developers copy commands from documentation pages without verifying that the displayed command and the downloaded script point to the same place.

Part of the PlainSec briefing for 2026-05-12

Sources