Weaponizing Trust Signals: Claude Code Lures and GitHub Release Payloads Deliver Vidar Stealer v18.7 + GhostSocks

Weaponizing Trust Signals (TL-2026-0403), also tracked as Claude Code Lure Campaign, is a high-severity malware campaign scored CVSS 8.1, first published 2026-04-21. It has no confirmed attribution, affects Microsoft Windows, maps to 33 MITRE ATT&CK techniques (T1005, T1016, T1027), and is covered by 9 detection rules and 20 indicators of compromise.

Key facts for TL-2026-0403

Threat ID
TL-2026-0403
Also known as
Claude Code Lure Campaign, leaked-claude-code Campaign, TradeAI Dropper Campaign, Vidar + GhostSocks GitHub Releases Campaign, idbzoomh1 Operation
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L)
Status
MONITORING
Category
MALWARE
First published
2026-04-21
Last reviewed
2026-04-21
Attribution confidence
NONE
Motivation
FINANCIAL
Target sectors
technology, software-development, cryptocurrency, financial, ai-research, general-consumer, freelance-developers, saas
Target regions
Global, North America, Europe, Asia-Pacific
Detection rules
9
Indicators of compromise
20

Malware and tooling in Weaponizing Trust Signals

Malware and tooling: GhostSocks, Vidar Stealer, Vidar v18.7, 7-Zip archive packaging

Financially motivated threat actors weaponized the 2026-03-31 Anthropic Claude Code npm packaging incident by standing up trojanized GitHub repositories branded 'leaked-claude-code' within 24 hours. The distribution hub github.com/leaked-claude-code/leaked-claude-code (owned by account idbzoomh1) served 7z archives containing a Rust-compiled dropper (TradeAI.exe / ClaudeCode_x64.exe) that installs Vidar Stealer v18.7 and GhostSocks SOCKS5 proxy malware. The Claude Code lure is one rotation in a broader campaign active since February 2026 that has impersonated 25+ software brands across 38 archives with 22 payload variants, abusing GitHub Releases as a trusted malware delivery channel.

How Weaponizing Trust Signals works

On 2026-03-31 Anthropic published a malformed Claude Code npm package that briefly exposed approximately 512,000 lines of internal TypeScript source via a 59.8 MB source map. Within 24 hours a threat actor using GitHub account 'idbzoomh1' created a public repository at github.com/leaked-claude-code/leaked-claude-code framed as a re-hosting of the 'leaked' Claude Code source. The repository README and releases lured visitors to download 7z archives that, instead of the advertised TypeScript, contained a Rust-compiled Windows PE dropper delivered under multiple filenames including TradeAI.exe and ClaudeCode_x64.exe.

Upon execution, the dropper decrypts and stages two payloads: Vidar Stealer v18.7 (a mature subscription-based infostealer) and GhostSocks (a Go-compiled SOCKS5 residential-proxy implant that converts victim machines into exit nodes for the operator's proxy service). Vidar v18.7 retains the family's signature dead-drop-resolver technique, using attacker-controlled Steam and Telegram profile pages to host obfuscated strings that resolve the current C2 endpoint, giving the operator cheap and resilient C2 rotation without DNS registration. Vidar harvests browser credentials, cookies, autofill data, cryptocurrency wallets (desktop and browser extensions), MFA/2FA tokens, FTP and email client credentials, Telegram and Discord session artifacts, screenshots, and system fingerprinting data before packaging the logs and exfiltrating them over HTTPS to the rotating C2. GhostSocks then establishes a persistent outbound SOCKS5 tunnel that the operator or downstream customer can relay traffic through, enabling follow-on fraud, account takeover, and anonymized access operations against the victim's IP reputation.

Trend Micro, Zscaler ThreatLabz, and SOC Prime independently track this Claude Code lure as one rotation in a broader rotating-brand campaign running continuously since February 2026. Trend Micro fingerprinted 25+ impersonated software brands across 38 distinct GitHub archive drops, paired with at least 22 payload variants of the Vidar + GhostSocks combo. Lures rotate to whatever news cycle favors them: trading and AI tooling ('TradeAI'), crypto wallets, VPNs, productivity apps, and now the Anthropic packaging incident. By 2026-04-07 the leaked-claude-code repository had accumulated 838 stars, 1,060 forks, and 533 confirmed payload downloads, and the operator had not been suspended by GitHub at the time of the initial Trend Micro publication.

The campaign is notable for weaponizing legitimate developer trust signals: (1) GitHub Releases are commonly whitelisted by endpoint and proxy policies; (2) the github.com TLS-fronted download URL passes most reputation checks; (3) star and fork counts are inflated by the operator's botnet to signal legitimacy; and (4) the timing of the Claude Code lure, within 24 hours of a real Anthropic incident, exploits defender and developer curiosity at its peak. Defenders should treat any 'leaked source' repository appearing immediately after a public incident as high-risk, inspect GitHub Release asset hashes against known-good artifacts, and instrument egress monitoring for the dead-drop-resolver beacons (Steam and Telegram profile fetches from non-browser processes) that are characteristic of Vidar v18.7.

MITRE ATT&CK techniques used in TL-2026-0403

Collection

T1005 Data from Local System; T1113 Screen Capture; T1115 Clipboard Data

Discovery

T1016 System Network Configuration Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery; T1518 Software Discovery

Defense Evasion

T1027 Obfuscated Files or Information; T1027.002 Obfuscated Files or Information: Software Packing; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1497 Virtualization/Sandbox Evasion

Exfiltration

T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service

Execution

T1059.003 Command and Scripting Interpreter: Windows Command Shell; T1204.002 User Execution: Malicious File

Command and Control

T1071.001 Application Layer Protocol: Web Protocols; T1090.002 Proxy: External Proxy; T1102.001 Web Service: Dead Drop Resolver; T1105 Ingress Tool Transfer; T1573.002 Encrypted Channel: Asymmetric Cryptography

Initial Access

T1189 Drive-by Compromise; T1195.002 Supply Chain Compromise: Compromise Software Supply Chain; T1566.002 Phishing: Spearphishing Link

Credential Access

T1539 Steal Web Session Cookie; T1552.001 Unsecured Credentials: Credentials In Files; T1555 Credentials from Password Stores; T1555.003 Credentials from Password Stores: Credentials from Web Browsers

Resource Development

T1583.006 Acquire Infrastructure: Web Services; T1585.001 Establish Accounts: Social Media Accounts; T1587.001 Develop Capabilities: Malware; T1588.001 Obtain Capabilities: Malware

Impact

T1657 Financial Theft

Affected products and versions in Weaponizing Trust Signals

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022
  • Anthropic — Claude Code (impersonated, not actually vulnerable)
    Vulnerable versions: n/a — brand abuse only
  • GitHub — GitHub Releases (abused distribution channel)
    Vulnerable versions: n/a — platform abuse

Remediation for Weaponizing Trust Signals

Patches

  • No vendor patch applies: this is a malware distribution campaign, not a software vulnerability
  • Anthropic revoked the malformed Claude Code npm artifact and re-published a clean package on 2026-03-31 — ensure all Claude Code installations are pulled from npm registry, not mirrored 'leaks'

Immediate actions

  • Block downloads from github.com/leaked-claude-code/* at web proxy and EDR
  • Hunt execution of TradeAI.exe and ClaudeCode_x64.exe across the fleet and isolate any hosts that executed them
  • Rotate all credentials, session cookies, MFA tokens, and cryptocurrency wallet keys on any host that executed either dropper
  • Block outbound HTTPS from non-browser processes to steamcommunity.com and t.me profile pages used as Vidar dead-drop resolvers
  • Quarantine any 7z archive with filenames matching claude-code-leaked*.7z, TradeAI*.7z, or ClaudeCode_x64*.7z at mail and web gateways

Workarounds

  • Filter GitHub Release downloads through a code-signing and hash-reputation gateway before execution
  • Use application allowlisting (WDAC, AppLocker) to block execution of unsigned user-land binaries

Longer-term hardening

  • Deploy EDR with behavioral detection for Rust-compiled droppers and dead-drop-resolver beaconing from non-browser processes
  • Restrict developer workstations from installing unsigned PE executables extracted from GitHub Release 7z archives
  • Add Vidar and GhostSocks YARA rules to endpoint scanners and email attachment sandboxing
  • Instrument DNS and HTTPS egress telemetry for Steam profile and Telegram t.me profile lookups from non-browser parent processes
  • Educate developers that 'leaked source' repositories appearing immediately after public incidents are a recurring malware lure pattern
  • Enroll developer laptops in attack-surface reduction rules that block execution from user-writable archive extraction paths

Weaknesses (CWE) in Weaponizing Trust Signals

CWE-506, CWE-807, CWE-494

Timeline of Weaponizing Trust Signals

  • Rotating-lure campaign using GitHub Releases begins; first impersonated brands include trading and crypto wallet apps. Vidar Stealer + GhostSocks payload pairing observed.
  • Campaign expands to multiple software brand impersonations. Trend Micro begins tracking as a unified operation linked by payload variants and GitHub account reuse patterns.
  • Anthropic publishes a malformed Claude Code npm package that exposes approximately 512,000 lines of internal TypeScript via a 59.8 MB source map. The bad artifact is withdrawn the same day.
  • First trojanized 7z archive drops TradeAI.exe and ClaudeCode_x64.exe Rust-compiled droppers that stage Vidar Stealer v18.7 and GhostSocks SOCKS5 proxy.
  • GitHub account 'idbzoomh1' creates repository github.com/leaked-claude-code/leaked-claude-code, pitched as a re-host of the leaked Claude Code source. Initial GitHub Release uploaded containing trojanized 7z archive.
  • BleepingComputer and The Register publish the first public exposure of the trojanized Claude Code lure.
  • Trend Micro, Zscaler ThreatLabz, and Help Net Security publish detailed analyses confirming Vidar v18.7 and GhostSocks payloads and linking the lure to the broader rotating-brand campaign.
  • SOC Prime releases hunt queries and Sigma rules for the Claude Code lure variant and the Vidar + GhostSocks payload chain.
  • leaked-claude-code repository recorded at 838 stars, 1,060 forks, and 533 confirmed payload downloads, with star/fork counts believed to be partially inflated by operator-controlled accounts.
  • Trend Micro publishes follow-up noting the Claude Code lure remains live weeks after initial disclosure; the operator rotates archive filenames and release tags to evade GitHub abuse takedowns.
  • Threadlinqs Intelligence publishes TL-2026-0403 with full MITRE mapping, IOC set, detection content, and attack simulation.
  • As of 2026-05-29, the specific Claude Code lure rotation has cooled as a news hook, but the broader rotating-brand campaign (active since Feb 2026, 25+ brands) and its tooling persist: Vidar is 2026's top infostealer and GhostSocks-via-GitHub abuse continues. The idbzoomh1 operator is unattributed with no arrest, takedown, or sinkhole; no CVE/patch applies.

Sources cited for Weaponizing Trust Signals

More in malware

Detection coverage for TL-2026-0403

As of 2026-04-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0403 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats