Fake Claude Code install guide on macOS used to drain crypto wallets
Security firm Huntress reverse-engineered MacSync, a six-stage macOS stealer and remote access Trojan spread via a paid Google ad. Victims clicked a result leading to a fake Claude Code install guide hosted under Anthropic's real certificate on claude.ai. The final stage replaced genuine Ledger and Trezor apps with fakes that harvested seed phrases, emptying crypto wallets.
Full text
Huntress reverse-engineers MacSync, a six-stage macOS stealer and remote access Trojan delivered through a fake Claude Code install guide hosted on a real claude.ai share URL and promoted via a paid Google ad
The lure needed almost no forgery: the page sat under Anthropic's own certificate, and the platform's safety banner repeated the attacker's chosen display name, "Apple Support," back to the reader as fact
The final stage rewrites installed Ledger and Trezor apps in place so a normal launch leads to a fake recovery message that harvests the seed phrase, draining the wallets of unsuspecting victims
Looking online for instructions on how to install Claude Code on a Mac could lead to you having your crypto wallet hijacked in the process
The victim ran a Google search, clicked the first result, a paid Google advertisement, and landed on a tidy step-by-step guide hosted on claude.ai, badged as shared by Apple Support, telling them to open Terminal and paste a single command.
What followed, according to a reverse-engineering write-up published by security firm Huntress was a six-stage macOS kill chain called MacSync: a stealer, a remote access trojan, a signed helper built to farm one specific system permission, and finally Trojanized copies of the victim's own cryptocurrency wallet apps, rewritten in place to phish the recovery phrase.
A complex, intricate approach that resulted in a stolen wallet
The victim had pulled their machine offline before Huntress could extract the malware from disk, so the researchers reconstructed the loader's request and instead downloaded every stage from the attacker's own delivery servers.
The results showed a sophisticated campaign that had to fake little to appear legitimate.
Anthropic lets any user publish a conversation to a public share URL. The operator maliciously used that feature exactly as designed. The lure page sat on claude.ai itself, over HTTPS, under Anthropic's own security certificates. There was no lookalike domain to squint at, no certificate warning to click past, and nothing in the address bar to give the game away.
The staging went much further than that. Whoever published the share set their display name to "Apple Support," and Anthropic's own safety banner, which sits directly above the content, duly reported that the reader was looking at a copy of a chat between Claude and Apple Support.
The platform repeated the attacker's chosen name back to the reader as established fact, further cementing their 'credentials'. The conversation itself was written to read like vendor documentation, promising that the install leaves personal files untouched and makes no system-level modifications without approval.
That same design decision has surfaced before for entirely different reasons. Wired had reported earlier private Claude conversations were turning up in Google and Bing results, because a share link is an ordinary public web page that search engines crawl like any other.
Users accidentally exposing their own chats and an operator deliberately planting a fake install guide are two outcomes of the same property: whatever gets published to a share URL is public, indexable, and served under Anthropic's certificate.
It is also not a one-off. Huntress has previously documented the same delivery pattern with AMOS through poisoned ChatGPT and Grok conversations, a separate remote access trojan through fake Claude desktop malvertising, and fake installers for other AI tools hosted on GitHub.
The lure has changed somewhat, but the shape has not, and users need to exercise caution when clicking links or following commands from untrustworthy sources on the internet, even if they appear to come from a source that Google was paid to place above the correct answer.
Similar stories
๐ช Crypto
Coldcard hacked in August 2026 โ are Ledger and Trezor wallets safe?
Bankier.pl ยท 3d ago
๐ป Technology
North Korean hackers compromised OPPO and 1,600+ firms in 57 countries via fake job interviews
Android Authority ยท 3d ago
๐ป Technology
SMOKE#SCREEN campaign uses fake Zoom and Adobe updates to install remote-access malware
TechRadar ยท 4d ago
Similar stories
๐ช Crypto
Coldcard hacked in August 2026 โ are Ledger and Trezor wallets safe?
Bankier.pl ยท 3d ago
๐ป Technology
North Korean hackers compromised OPPO and 1,600+ firms in 57 countries via fake job interviews
Android Authority ยท 3d ago
๐ป Technology
SMOKE#SCREEN campaign uses fake Zoom and Adobe updates to install remote-access malware
TechRadar ยท 4d ago
Should Google be held responsible for malicious ads in search results?
Comments
No comments yet
Comments
No comments yet โ be the first to weigh in ๐
No comments yet. Be the first!