Malicious GitHub Repository Delivers Stealing Malware via Fake AI Software
A malicious GitHub repository impersonating Anthropic has been delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials.
The campaign relies on social engineering, with victims steered to game-cheat-themed sites. The repository offers a download named ClaudeOpus5-desktop.zip, listed at about 101 MB, alongside screenshots and model comparison charts.
Running the file opens no window, but instead checks the computer's memory, processor count, hostname and username against a blocklist, adds the user's AppData folder to the Windows Defender exclusion list, decrypts a bundled file, and launches RevStealer in the background.
The malware targets browser databases and saved credentials, extension storage, Windows Credential Manager entries, files from password managers, cryptocurrency wallet applications, VPN and remote access credentials, messaging app data, game launcher accounts, OBS streaming profiles, clipboard content, screenshots and selected user documents.