Independent verification and platform response will determine whether an Anthropic-hosted, Google-ranked Claude artifact impersonated Claude Code installation guidance and delivered a macOS infostealer.
state: expiredheat: lowuncertainty: highknownscott: mediumagentic-security supply-chain-security developer-toolsAnthropicGoogle
What is this?
Security reports describe attackers abusing publicly hosted Claude artifacts or bogus Claude-branded installation guides surfaced through Google Search or Google Ads, using copy-and-paste terminal instructions to infect macOS users with infostealers. Reports attribute related research to MacPaw’s Moonlock Lab and AdGuard, while Anthropic operates the Claude platform and Google provides the search/advertising surface. The supplied snippets do not independently establish that the specific artifact impersonated Claude Code installation guidance, whether it ranked organically or through ads, or which named infostealer it delivered; they appear to cover several related campaigns and malware families.
Why it matters to Scott
The radar already tracks both halves of this alleged mechanism in “claude-shares-google-indexing” and “codex-sponsored-ad-malware”: indexable Claude-hosted material and search-distributed fake coding-tool installation instructions. It matters because Scott actively uses Claude Code and argues for independently verified artefacts and constrained execution, but the specific incident remains unverified and currently extends rather than changes those positions.
ip:concept.cryptographic-trustip:framework.agent-provenance-stackip:framework.architecture-not-vibesdev:concept.padded-cell-agent-architecturedev:technology.claude-codedev:project.askradar:claude-shares-google-indexingradar:codex-sponsored-ad-malwareradar:concept.software-supply-chain
queries asked of Scott's wikis
- developer-tool installation trust boundaries
- curl-to-shell and copy-paste command security
- agent-generated artifacts as a software supply chain
- search ranking and ads as malware distribution
- coding-agent onboarding and installer verification
- platform responsibility for hosted AI artifacts
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (1) — ⭐ canonical anchor
Interpretation history
2026-08-22T19:37:37Z
After 48 hours, no artifact URL, payload indicators, reproducible search result, independent verification, or platform response has emerged; activity remains repetitive amplification of one report. The specific incident is still plausible but unsubstantiated and no longer merits active tracking absent fresh evidence.
2026-08-20T18:34:43Z
Refreshed comments remain generic security commentary and victim-blaming rather than independent verification. Without an artifact URL, payload indicators, reproducible search result, or platform response, the case’s meaning is unchanged.
2026-08-20T16:43:07Z
The additional activity is repetitive amplification, not independent verification: no artifact URL, script, indicators, reproducible search result, or platform response has appeared. The alleged incident remains plausible but unsubstantiated and has not advanced beyond a single-source report.
2026-08-20T16:30:55Z
grounded: known/medium — The radar already tracks both halves of this alleged mechanism in “claude-shares-google-indexing” and “codex-sponsored-ad-malware”: indexable Claude-hosted mate
2026-08-20T16:26:27Z
case created — The report describes a specific, consequential software-supply-chain incident involving trusted hosting, search discovery, and executable installation instructions.
Decision trace
- 08-23 05:37expireAfter 48 hours, no artifact URL, payload indicators, reproducible search result, independent verification, or platform response has emerged; activity remains repetitive amplification of one report. Th
- 08-23 05:37alert_silentThe only new delta is elapsed time without corroboration; engagement alone does not establish the alleged incident or justify interrupting Scott.
- 08-23 05:37alert_routeThe only new delta is elapsed time without corroboration; engagement alone does not establish the alleged incident or justify interrupting Scott.
- 08-22 06:21sensor_dirtyengagement_update
- 08-22 04:21sensor_dirtyengagement_update
- 08-21 19:21sensor_dirtyengagement_update
- 08-21 18:21sensor_dirtyengagement_update
- 08-21 15:21sensor_dirtyengagement_update
- 08-21 13:21sensor_dirtyengagement_update
- 08-21 11:21sensor_dirtyengagement_update
- 08-21 10:21sensor_dirtyengagement_update
- 08-21 09:21sensor_dirtyengagement_update
- 08-21 08:21sensor_dirtyengagement_update
- 08-21 07:21sensor_dirtyengagement_update
- 08-21 06:21sensor_dirtyengagement_update
- 08-21 05:21sensor_dirtyengagement_update
- 08-21 04:34repriceRefreshed comments remain generic security commentary and victim-blaming rather than independent verification. Without an artifact URL, payload indicators, reproducible search result, or platform resp
- 08-21 04:34alert_silentThe new delta is only repetitive discussion and adds no confidence that the alleged incident occurred; it can wait for inspectable evidence, independent reproduction, or an Anthropic/Google response.
- 08-21 04:34alert_routeThe new delta is only repetitive discussion and adds no confidence that the alleged incident occurred; it can wait for inspectable evidence, independent reproduction, or an Anthropic/Google response.
- 08-21 04:21sensor_dirtycomment_update
- 08-21 03:21sensor_dirtycomment_update
- 08-21 02:43repriceThe additional activity is repetitive amplification, not independent verification: no artifact URL, script, indicators, reproducible search result, or platform response has appeared. The alleged incid
- 08-21 02:43alert_silentOnly Reddit engagement increased; no consequential evidence changed whether the incident occurred, so alerting would still overstate confidence and can wait for independent reproduction or a platform
- 08-21 02:43alert_routeOnly Reddit engagement increased; no consequential evidence changed whether the incident occurred, so alerting would still overstate confidence and can wait for independent reproduction or a platform
- 08-21 02:38alert_silentA lone Reddit post alleges an active, Google-ranked malware path through an Anthropic-hosted artifact, but provides no inspectable artifact URL, script, malware indicators, search-result capture, or p
- 08-21 02:38surface_candidateA lone Reddit post alleges an active, Google-ranked malware path through an Anthropic-hosted artifact, but provides no inspectable artifact URL, script, malware indicators, search-result capture, or p
- 08-21 02:38alert_routeA lone Reddit post alleges an active, Google-ranked malware path through an Anthropic-hosted artifact, but provides no inspectable artifact URL, script, malware indicators, search-result capture, or p
- 08-21 02:30groundThe radar already tracks both halves of this alleged mechanism in “claude-shares-google-indexing” and “codex-sponsored-ad-malware”: indexable Claude-hosted material and search-distributed fake coding-
- 08-21 02:26createThe report describes a specific, consequential software-supply-chain incident involving trusted hosting, search discovery, and executable installation instructions.