GoPlus Warns Fake Claude Code Pages in Google Search Ads Steal Wallets and Credentials

According to GoPlus, malicious Google Search results and ads for Claude Code led users to cloned install pages designed to steal login data, crypto wallets, and other sensitive system information.

Summary

GoPlus warned on March 11 that top Google Search results and sponsored ads for Claude Code were serving malicious installers through pixel-perfect copies of the official download pages. According to the alert, the malware was built to steal passwords, cookies, session tokens, crypto wallets, account credentials, and system information. The warning highlights a search-ad phishing tactic in which attackers imitate legitimate software pages to distribute malware and capture sensitive data.

Terms & Concepts
  • Session tokens: Authentication data that keeps a user logged in and can be abused by attackers to hijack accounts.
  • Crypto wallets: Tools that store private keys and enable users to access, send, and manage digital assets.