Malware disguised as Anthropic’s leaked Claude source code is actively circulating across hacker forums, according to a report from Wired. Threat actors are bundling the leaked files with malicious payloads, turning a high-profile AI leak into a trap for developers and researchers curious enough to download it.
Hackers Distribute Leaked Claude Code Alongside Malicious Software: Everything You Need to Know
Hackers have been posting what appears to be Anthropic’s “Claude leaked” source code on underground forums — but there’s a problem. The files come bundled with embedded malware that targets anyone who downloads and runs the package. It’s a classic move: exploit curiosity around a valuable leak, then slip in the malicious payload.
Researchers first flagged this activity in late March 2026. Within days, the distribution had spread across Telegram channels and dark web repositories.

The Real Impact on Developers and AI Security
Developers are the real target here, and it’s intentional. Engineers working with AI tools often run unfamiliar code locally without proper sandboxing. That’s exactly what the attackers are counting on.
The malware bundled in these packages steals credentials, API keys, and environment variables. This isn’t just about compromising one machine — attackers want cloud access tokens and model API credentials that can unlock much broader infrastructure access. Worth noting: Anthropic has already moved to limit Claude access in response to ongoing misuse concerns, but the leaked code predates those controls.
What We Know: Dates, Details & Scope
Late March 2026 — first confirmed sightings on hacker forums.
Multiple delivery vectors — Telegram, dark web paste sites, and private Discord servers.
Payload type — credential-stealing malware, with some variants including remote access trojans (RATs).
Target profile — AI developers, researchers, and hobbyists running local Claude builds.
The bigger question: how many machines are already infected? We don’t have exact numbers yet, but the speed of distribution across at least three separate platforms suggests this is a coordinated campaign, not just opportunistic activity.
What Security Experts Are Saying
Security researchers are describing this as a supply-chain-adjacent attack. It’s not a classic supply chain compromise, but it produces the same damage. Recent military software failures showed us how trusted code channels can be weaponized.
The advice from experts is straightforward: verify file hashes before executing any Claude-related code downloaded outside official Anthropic repositories. One researcher summed it up bluntly: “If you didn’t get it from Anthropic’s official source, assume it’s poisoned.”
How This Threat Evolves From Here
Expect malware variants to multiply as the original leak spreads. Threat actors will repackage and re-upload files across new platforms as old ones get taken down — it’s a whack-a-mole game that security teams know all too well.
Anthropic is expected to release formal guidance soon. Until then, stick with the basics: don’t download unverified Claude code from unofficial sources, and audit any environment where such files might’ve already landed.
People Also Ask
Q: What malware is being distributed with the Claude code leak?
Credential-stealing malware and remote access trojans (RATs) have been identified bundled with the leaked Claude source code files circulating on hacker forums and Telegram channels.
Q: Is the Claude source code leak real?
Researchers believe the leaked files contain genuine Anthropic code, though Anthropic hasn’t issued a full public confirmation as of early April 2026.
Q: How can developers protect themselves from this malware?
Verify file hashes against official sources, avoid downloading Claude-related code from unofficial channels, and audit any environment where unverified files may have been executed.
Q: What should I do if I already downloaded the Claude leak files?
Isolate the affected machine immediately, rotate all API keys and cloud credentials stored in that environment, and run a full security scan before reconnecting to any network.





