Categories: Tech

Bybit Uncovers macOS Malware Campaign Targeting Claude Code Developers and Crypto Wallets

Bybit’s Security Operations Center has uncovered a sophisticated macOS malware campaign targeting developers searching for Claude Code, an AI-powered coding tool from Anthropic, highlighting a growing intersection between AI adoption and crypto-focused cyber threats. The attack uses search engine manipulation to trick users into downloading malicious software that can steal credentials, access crypto wallets, and establish persistent control over infected systems. 


Fake Claude Code Downloads Used to Infect Developers

Attackers are exploiting the popularity of Claude Code by pushing malicious links to the top of search results through SEO poisoning. Victims searching for the tool are redirected to fake websites designed to mimic official documentation, where they unknowingly download infected files.  The attack chain is multi-stage and begins with a disguised installer that deploys malware immediately after execution.


Malware Targets Crypto Wallets and Sensitive Data

Once installed, the malware acts as an infostealer, extracting a wide range of sensitive data from the victim’s system.

This includes:

  • Browser credentials and saved passwords
  • macOS Keychain data
  • Telegram sessions and VPN profiles
  • Crypto wallet data and private keys

Bybit researchers identified attempts to access hundreds of crypto wallet extensions, showing that digital assets are a primary target of the campaign.


Advanced Backdoor Enables Persistent System Control

Beyond data theft, the malware deploys a secondary backdoor written in C++, allowing attackers to maintain long-term access to compromised devices.

The system includes:

  • Encrypted communication with remote servers
  • Sandbox detection to evade security tools
  • Persistent system agents to survive reboots

This turns infected machines into ongoing access points rather than one-time targets.


AI Tools Become a New Attack Surface

This campaign reflects a broader trend where cybercriminals are targeting developers through AI tools and platforms. As tools like Claude Code gain adoption, attackers are exploiting trust in these systems to distribute malware more effectively. The strategy is simple but effective. Instead of hacking systems directly, attackers trick users into installing compromised tools themselves.

Terron Gold

Recent Posts

Elon Musk’s xAI Sues Minnesota Over First U.S. AI Nudification Law

Elon Musk's artificial intelligence company xAI has filed a federal lawsuit challenging Minnesota's landmark law banning AI-powered "nudification" technology, arguing…

6 days ago

Bitcoin Nears $65,000 as Treasury Yields Outperform Carry Trade in Rare Market Signal

Bitcoin climbed toward $65,000 as an unusual shift in traditional financial markets created one of the rarest conditions…

6 days ago

Hyperscale Data Sells 100 Bitcoin to Fund Michigan AI Campus as GPUS Stock Surges

Hyperscale Data has sold 100 Bitcoin to accelerate development of its planned artificial intelligence campus in Michigan, sending shares…

7 days ago

PIPEDOG Explodes 140x on Robinhood Chain as Memecoin Frenzy Intensifies

A newly launched memecoin called PIPEDOG ($PIPEDOG) became the latest breakout token on Robinhood Chain, surging more than 140x within…

1 week ago

BNY Brings $8.6 Trillion Fund Business On-Chain in Major Wall Street Blockchain Expansion

BNY, the world's largest custodian bank, is bringing one of its core financial businesses onto…

1 week ago

Senators Strengthen Crypto Ethics Rules in CLARITY Act After Trump Negotiations

A bipartisan group of U.S. senators has reportedly reached a new compromise on the ethics provisions of…

1 week ago