Fake Claude Code site served trojan — detected by Windows Defender as Trojan:Win32/Kepavll!rfn

✍️ OpenClawRadar📅 Published: May 10, 2026🔗 Source
Fake Claude Code site served trojan — detected by Windows Defender as Trojan:Win32/Kepavll!rfn
Ad

A Reddit user on r/ClaudeAI reported that the first Google search result for "Claude Code" was a fake website with the exact same design language as the official Anthropic site. After downloading and running a PowerShell install command, Windows Defender caught the payload as Trojan:Win32/Kepavll!rfn.

What happened

  • The user, who has been online since 1996 and works mostly on macOS, needed to use Claude Code on a rarely used Windows PC.
  • Clicked the first Google result for "Claude Code" — the site looked identical to the official one.
  • Ran the PowerShell install command (similar to the legitimate iex (irm <url>) pattern) without verifying the URL.
  • Windows Defender immediately flagged the download as Trojan:Win32/Kepavll!rfn.
Ad

How to avoid this

  • Always check the domain: official Claude Code downloads are on docs.anthropic.com or the official GitHub repository, not a lookalike.
  • For Windows, use winget install ClaudeCode or download the MSI directly from the official source.
  • Never run iex (irm ...) from a search result — manually verify the URL before pasting into PowerShell.

📖 Read the full source: r/ClaudeAI

Ad

👀 See Also

ClawSecure: Security Platform for OpenClaw Ecosystem
Security

ClawSecure: Security Platform for OpenClaw Ecosystem

ClawSecure is a security platform built specifically for the OpenClaw ecosystem, featuring a 3-layer audit protocol, continuous monitoring, and coverage of OWASP ASI categories. It has audited 3,000+ popular skills and is available free with no signup.

OpenClawRadar
NPM Compromise via Axios Backdoor: Impact on AI Coding Agents
Security

NPM Compromise via Axios Backdoor: Impact on AI Coding Agents

On March 31, 2026, a DPRK-linked threat actor compromised npm by publishing backdoored versions of Axios (1.14.1 and 0.30.4) during a 3-hour window. The malware injected a dependency that downloaded a platform-specific RAT, harvested credentials, and self-erased, with AI coding agents like Claude Code and Cursor being particularly vulnerable due to automated npm installs.

OpenClawRadar
Claude Code Plugin Bug Causes CPU Spikes and Battery Drain
Security

Claude Code Plugin Bug Causes CPU Spikes and Battery Drain

A user discovered that Claude Code's Telegram plugin spawns multiple bun.exe processes that run at 100% CPU even with the laptop lid closed, causing rapid battery drain. The processes survive sleep/wake cycles and require specific cleanup steps to remove.

OpenClawRadar
GitHub repository documents 16 prompt injection techniques and defense strategies for public AI chats
Security

GitHub repository documents 16 prompt injection techniques and defense strategies for public AI chats

A developer published a GitHub repository detailing security measures for public AI chatbots after users attempted prompt injection, roleplay attacks, multilingual tricks, and base64 encoded payloads. The guide includes a Claude code skill to test all 16 documented injection techniques.

OpenClawRadar