Malicious Claude Artifact Ranks on Google, Distributing macOS Stealer via Fake Install

PressureGullible547 · reddit · 2026-08-20

A user searching for "Claude Code install" clicked a top Google result hosted on an official Anthropic domain (a malicious published artifact). Executing the provided curl ... | bash script, which looked legitimate, actually installed a macOS infostealer with persistent launch agents. The user had to wipe the disk after realizing the breach. This serves as a warning to verify sources before running installation scripts.

Original post →

More from Safety

Safety channel →