Claude Code源码泄露事件还没平息,黑客已经开始趁火打劫了。安全公司Zscaler发现,有黑客在GitHub上创建虚假仓库,声称提供”解锁企业功能”的泄露源码,实际上是在传播Vidar信息窃取恶意软件The
事件回顾
Previously.Anthropic公司由于人为操作失误,其终端AI工具Claude Code的完整前端源码被意外打包进npm公开包中,导致51.3万行代码外泄。这一事件在开发者社区引发了广泛关注。
黑客的钓鱼套路
名为idbzoomh的用户抓住这个热点,在GitHub建立了虚假仓库,声称提供”解锁企业功能”的泄露源码。该黑客还针对性优化了搜索引擎索引,导致用户搜索相关关键词时极易中招。
用户一旦下载并运行其中的可执行文件,Vidar信息窃取程序便会入驻系统,同时部署GhostSocks代理工具。
Vidar是什么
Vidar是暗网明码标价的成熟恶意软件,专攻浏览器数据、加密货币钱包等敏感信息。研究人员指出,该虚假仓库内的恶意压缩包更新频繁,未来可能携带更多攻击载荷。
提醒所有开发者:不要轻易下载来源不明的”泄露源码”,这很可能是黑客精心设计的陷阱。
This article comes from users or anonymous contributions, does not represent the position of Mass Intelligence; all content (including images, videos, etc.) in this article are copyrighted by the original author. Please refer to this site for the relevant issues involvedstatement denying or limiting responsibilityPlease contact the operator of this website for any infringement of rights (Contact Us)我们将按声明中的处理方式进行处理。本文链接:https://dzzn.com/en/2026/3911.html