← Back to Feed
Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads
April 3, 2026 · Trend Micro · Severity: MEDIUM
A packaging error in Anthropic’s Claude Code npm release briefly exposed internal source code. This entry examines how threat actors rapidly weaponized the resulting attention, pivoting an existing AI-themed campaign to spread Vidar and GhostSocks.
Key Takeaways
- A packaging error in Anthropic's Claude Code npm release briefly exposed internal source code, drawing attacker attention.
- Threat actors rapidly weaponized the resulting attention by pivoting an existing AI-themed campaign to spread Vidar and GhostSocks malware.
- Organizations should treat AI-themed lures and GitHub release payloads as high-risk vectors and verify all downloaded tools.