Attackers Hijack Claude Code Install Pages

Push Security researchers warn attackers are cloning Anthropic’s Claude Code installation page and using paid Google Search ads to surface lookalike domains that swap legitimate install instructions for malicious commands. The fake pages redirect to Anthropic’s site but replace install one-liners to download Amatera Stealer on Windows and similar info‑stealers on macOS. Developers risk credential theft unless they verify URLs and avoid pasting unknown install commands.
Scoring Rationale
Credible Push Security finding with actionable mitigations, but limited novelty beyond a targeted malvertising campaign affecting developers.
Practice with real Ad Tech data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Ad Tech problemsStep-by-step roadmaps from zero to job-ready — curated courses, salary data, and the exact learning order that gets you hired.
Sources
- Read OriginalFake Claude Code install pages highlight rise of “InstallFix” attackshelpnetsecurity.com


