PANews reported on March 11 that, according to a security alert issued by GoPlus, attackers are using Google search ads to deliver malware that is a pixel-perfect clone of the official #Claude Code installation page. This malware steals user passwords, cookies, session tokens, Crypto wallets, credentials, and system information. GoPlus recommends identifying ad icons in search results and carefully verifying subtle differences between the URL and the official website; verifying installation methods through multiple channels such as official documentation, social media, or GitHub repositories; not executing unfamiliar commands directly, but analyzing command line behavior before running them; and installing security plugins to block phishing links, risky signatures, authorizations, and transactions in real time.


