CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

InstallFix Attacks Distribute Amatera Infostealer via Fake Claude Code Install Guides

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

Threat actors are using a new social engineering technique called InstallFix to trick users into executing malicious commands under the guise of installing legitimate CLI tools, such as Claude Code. The attackers create cloned installation pages with malicious commands that deliver the Amatera infostealer. The campaigns are promoted through malvertising on Google Ads, targeting users searching for installation guides. The Amatera infostealer steals browser credentials, cookies, and session tokens while evading detection.

Timeline

  1. 06.03.2026 17:00 1 articles · 11h ago

    InstallFix Attacks Distribute Amatera Infostealer via Fake Claude Code Install Guides

    Threat actors are using a new social engineering technique called InstallFix to trick users into executing malicious commands under the guise of installing legitimate CLI tools, such as Claude Code. The attackers create cloned installation pages with malicious commands that deliver the Amatera infostealer. The campaigns are promoted through malvertising on Google Ads, targeting users searching for installation guides. The Amatera infostealer steals browser credentials, cookies, and session tokens while evading detection.

    Show sources

Information Snippets