Bybit Unveils macOS Malware Campaign Targeting Claude Code Developers
Bybit, the world's second-largest cryptocurrency exchange by trading volume, has uncovered a sophisticated malware campaign targeting macOS users searching for 'Claude Code', an AI-powered development tool.
The Security Operations Center (SOC) at Bybit discovered the campaign, which used search engine optimization (SEO) poisoning to elevate a malicious domain to the top of Google search results in March 2026. Users were redirected to a spoofed installation page that closely resembled legitimate documentation, triggering a two-stage attack chain focused on credential harvesting and persistent system access.
The initial payload delivered via a Mach-O dropper deployed an osascript-based infostealer with characteristics similar to known AMOS and Banshee variants. It executed a multi-phase obfuscation sequence to extract sensitive data including browser credentials, macOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet information.
The malware also targeted over 250 browser-based wallet extensions and multiple desktop wallet applications. A second-stage payload introduced a C++-based backdoor with advanced evasion capabilities, including sandbox detection and encrypted runtime configurations.
Bybit's SOC leveraged AI-assisted workflows to accelerate response time while maintaining analytical depth. The company's AI-assisted SOC allowed it to move from detection to full kill chain visibility within a single operational window.