2026-10-11 17:12 UTC

Independent verification and platform response will determine whether an Anthropic-hosted, Google-ranked Claude artifact impersonated Claude Code installation guidance and delivered a macOS infostealer.

state: expiredheat: lowuncertainty: highknownscott: mediumagentic-security supply-chain-security developer-toolsAnthropicGoogle

What is this?

Security reports describe attackers abusing publicly hosted Claude artifacts or bogus Claude-branded installation guides surfaced through Google Search or Google Ads, using copy-and-paste terminal instructions to infect macOS users with infostealers. Reports attribute related research to MacPaw’s Moonlock Lab and AdGuard, while Anthropic operates the Claude platform and Google provides the search/advertising surface. The supplied snippets do not independently establish that the specific artifact impersonated Claude Code installation guidance, whether it ranked organically or through ads, or which named infostealer it delivered; they appear to cover several related campaigns and malware families.

Why it matters to Scott

The radar already tracks both halves of this alleged mechanism in “claude-shares-google-indexing” and “codex-sponsored-ad-malware”: indexable Claude-hosted material and search-distributed fake coding-tool installation instructions. It matters because Scott actively uses Claude Code and argues for independently verified artefacts and constrained execution, but the specific incident remains unverified and currently extends rather than changes those positions.
ip:concept.cryptographic-trustip:framework.agent-provenance-stackip:framework.architecture-not-vibesdev:concept.padded-cell-agent-architecturedev:technology.claude-codedev:project.askradar:claude-shares-google-indexingradar:codex-sponsored-ad-malwareradar:concept.software-supply-chain
queries asked of Scott's wikis
  • developer-tool installation trust boundaries
  • curl-to-shell and copy-paste command security
  • agent-generated artifacts as a software supply chain
  • search ranking and ads as malware distribution
  • coding-agent onboarding and installer verification
  • platform responsibility for hosted AI artifacts

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (1) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟠 reddit ⭐PSA: a malicious published Claude artifact is ranking on Google for Claude Code install queries — it installed a macOS infostealer on my Mac
ClaudeAI
PressureGullible54717446

Interpretation history

Decision trace