Claude Code Install Phishing Site Tops Google Search Results

✍️ OpenClawRadar📅 Published: July 6, 2026🔗 Source
Claude Code Install Phishing Site Tops Google Search Results
Ad

A Reddit user on r/ClaudeAI reports that searching Google for "Claude code install mac" returns a phishing site as the top result, masquerading as the official Claude Code download page. The fake page is designed to trick developers into downloading malware or stealing credentials.

What's Happening

  • The phishing site appears as the first Google result for the search term "Claude code install mac".
  • It mimics the official Anthropic/Claude branding and UI to appear legitimate.
  • Users who download software from the fake site risk installing malicious payloads or exposing sensitive data.

How to Stay Safe

Always verify the domain before downloading Claude Code. The only official source is https://docs.anthropic.com/en/docs/claude-code/overview or directly from Anthropic's verified distribution channels. Check the URL carefully — phishing sites often use slight misspellings or different TLDs.

Who Is Affected

Developers on macOS searching for Claude Code installation instructions are the primary target. The attack exploits trust in search engine rankings.

📖 Read the full source: r/ClaudeAI

Ad

👀 See Also

Potential Claude Security Incident: Self-Sent Password Alerts and Suspicious .NET Process
Security

Potential Claude Security Incident: Self-Sent Password Alerts and Suspicious .NET Process

A user reports receiving suspicious password reset alerts that appeared to be sent from their own account after logging into Claude, with emails vanishing minutes later and an unusual .NET process blocking system shutdown.

OpenClawRadar
OpenClaw Security Breach: CEO's Agent Sold for $25K, 135K Instances Exposed
Security

OpenClaw Security Breach: CEO's Agent Sold for $25K, 135K Instances Exposed

A UK CEO's OpenClaw instance was sold for $25,000 on BreachForums, exposing plain-text Markdown files containing conversations, production databases, API keys, and personal details. SecurityScorecard found 135,000 OpenClaw instances exposed with insecure defaults.

OpenClawRadar
Cisco source code stolen via Trivy supply chain attack
Security

Cisco source code stolen via Trivy supply chain attack

Cisco's internal development environment was breached using stolen credentials from the Trivy supply chain attack, resulting in the theft of source code from over 300 GitHub repositories including AI-powered products and customer code.

OpenClawRadar
Open Source AI Tools Pose Security Risks Through 'Illusory Security Through Transparency'
Security

Open Source AI Tools Pose Security Risks Through 'Illusory Security Through Transparency'

A Reddit post warns about malware disguised as open-source AI agents and tools, where malicious code can be hidden in large codebases that users assume are safe because they're on GitHub. The post describes how 'vibe-coding' and autonomous AI agents condition users to run unknown programs without review.

OpenClawRadar