Threats · 126 days ago
The browser is the attack surface here, not the download URL. A developer can see a normal-looking Claude Code install page, copy the command, and still pull a stealer from an attacker domain because the page text is altered while the fetched PowerShell file looks clean.
Ontinue tied the campaign to three operator-controlled domains registered in April 2026 and a lure pushed through sponsored search results for "install claude code." The payload targets Chromium-based browsers, including Chrome, Edge, Brave, Vivaldi, Perplexity Comet, and Arc, and steals cookies, passwords, and payment data from developer workstations.
This pattern defeats fetch-based scanning and turns search-driven install workflows into credential theft. The risk persists anywhere developers copy commands from documentation pages without verifying that the displayed command and the downloaded script point to the same place.
2 sources covering this story
Cookie thieves caught stealing dev secrets via fake Claude Code installers
New IElevator2 COM interface? No problem
Fake Claude Code Page Pushes PowerShell Stealer at Devs
Ontinue uncovers fake Claude Code installer pushing PowerShell stealer abusing Chrome's IElevator2
Part of the PlainSec briefing for 2026-05-12