// Alert

Claude threat report

Between June 12–19, 2026, threat actors ran a malicious campaign exploiting Claude's shared-chat feature to distribute MacSync Stealer malware to macOS users. Attackers purchased Google Ads redirecting searches for "Claude" to malicious shared chats impersonating Apple Support, instructing victims to paste terminal commands that deployed a multi-stage payload. The stealer harvested credentials, browser data, SSH keys, cryptocurrency wallets, and other sensitive files via the ClickFix social engineering technique.

// Get alerts for Claude