Cyphorix
الذهاب إلى القناة على Telegram
Cybersecurity | Ethical Hacking | OSINT 📚 Courses • Premium Resources • Ebooks 🧪 Tools • Labs • Real Techniques 💻 Learn Real Cybersecurity Skills 🚀 Join & Level Up Your Knowledge https://tr.ee/9XgmJf
إظهار المزيدلم يتم تحديد البلدالفئة غير محددة
451
المشتركون
+2124 ساعات
+487 أيام
+17830 أيام
أرشيف المشاركات
455
🚨 AI SECURITY ALERT
🎯 Topic: Claude Code Backdoor – Malicious GitHub Repo (Social Engineering Attack)
🔗 Repository
📂 GitHub
https://github.com/s0ld13rr/claude-code-backdoor
🧠 Overview
This repository is part of a real-world attack pattern targeting developers:
➡️ Fake / malicious GitHub projects disguised as AI tools
It leverages the recent hype around Claude Code leaks to trick users into:
• Cloning repositories
• Running setup commands
• Executing hidden malicious code
⚠️ Threat Context
After the Claude Code source leak incident, attackers began:
• Publishing fake repositories
• Claiming “unlocked” or “leaked” versions
• Embedding malware / backdoors
➡️ These repositories are designed to exploit curiosity.
☠️ Backdoor Behavior (Real Case)
Security analysis revealed patterns like:
🔴 Remote Code Execution (RCE)
• Hidden scripts triggered during:
npm run dev
• Fetches remote payload
• Executes silently
• Full system access granted
➡️ Filesystem / network / process control
🕵️ Stealth Execution
• No visible output
• Errors suppressed
• Runs in background
🎭 Fake Functionality
• Fake AI features
• Mock data instead of real backend
• Frontend hides failures
➡️ Designed to appear legitimate
🎯 Attack Method
This is not just malware.
👉 It is a social engineering campaign
Typical flow:
1️⃣ Victim contacted (LinkedIn / freelance offer)
2️⃣ Asked to review GitHub project
3️⃣ Encouraged to run code
4️⃣ Backdoor executes silently
➡️ Full compromise achieved
🧪 Real Malware Campaigns
Recent attacks used:
• Fake “Claude Code leak” repos
• Rust-based executables
• Infostealers like Vidar
➡️ Stealing:
Passwords
Browser data
Crypto wallets
⚔️ Offensive Insight
This is a new attack trend:
Traditional:
➡️ Phishing links
Now:
➡️ GitHub-based supply chain attacks
Why it works:
• Developers trust GitHub
• AI hype lowers skepticism
• “Leaked tools” attract clicks
🚨 Red Flags
Watch for:
• “Leaked / Unlocked AI” claims
• One-command install scripts
• Obfuscated code
• Unexpected network calls
• No real backend implementation
🛡 Defensive Recommendations
✔️ Never run unknown repositories blindly
✔️ Always audit code before execution
✔️ Use sandbox / VM environments
✔️ Monitor outbound network activity
✔️ Verify repository authenticity
🔥 Key Takeaway
This is NOT just a repository.
➡️ It represents a real-world developer targeting attack
Combining:
• AI hype
• Social engineering
• Supply chain compromise
🎯 Final Verdict
❗️ High Risk
❗️ Potential Backdoor / Malware
❗️ Social Engineering Trap
🔥 Critical Message
👉 If you run untrusted code,
👉 you are already compromised.455
🔥 CCNP Security – Advanced Training (Concept-Focused) 🔥
CBT Nuggets – Cisco CCNP Security 300-207 (SITCS)
⚠️ Note: This is an older exam version, but the security concepts are still highly relevant for real-world networking & security roles.
✅ Enterprise network security fundamentals
✅ VPN, secure access & threat protection
✅ Useful for learning & skill-building (not latest exam prep)
📥 Drive Access:
👉 Link
455
Ethical Hacking from Zero to Hero 🚀
Start your journey in cybersecurity the right way.
This free course takes you from beginner fundamentals to advanced concepts used in real-world security testing and defense strategies.
Build skills. Think like a hacker.
Download: https://drive.google.com/drive/u/0/mobile/folders/15J_qMzQ8TEI4VIjSF_0g6Rpf-fi2wVBl
#cybersecurity #ethicalhacking #infosec #learning #bugbounty #pentesting
