
Researchers have identified a new InstallFix malware campaign targeting developers through fake Claude Code installation guides. This social engineering attack tricks users into manually executing malicious commands that deploy infostealers like Amatera (Windows) and MacSync(macOS).
Attack Vector and Social Engineering
The campaign leverages “perfect clones” of official documentation to gain user trust:
Technical Execution
The malicious commands vary by platform but prioritize stealth and fileless execution:
mshta.exe (a signed Microsoft binary) to fetch and execute a remote HTA payload directly in memory. This triggers the installation of the Amatera infostealer, which targets browser passwords, cookies, and session tokens.curlcommand that decodes a Base64 string and pipes it directly into the Zsh shell. This installs MacSync, an infostealer capable of harvesting Keychain passwords and crypto wallets.Protective Measures
To avoid these attacks, developers should:
code.claude.com) for installation instructions.curl or powershellcommands to ensure the destination URL is legitimate. #attacks #claude #code #deliver #guides #infostealers #installfix #malicious #news #via — News
© Bulletproof Servers. All rights reserved.