INTEL_REPORT
Trend Micro Research · published 4/7/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do Threat actors leveraged Anthropic’s Claude Code npm release packaging error to distribute Vidar, GhostSocks, and PureLog Stealer. This blog details immediate steps organizations can take and best practices to prevent further risk. Claude Code Packaging Error Remains a Lure in an Active Campaign: What Defenders Should Do | Trend Micro (US) search close About Mission and Culture Mission…
https://www.trendmicro.com/en_us/research/26/d/claude-code-remains-a-lure-what-defenders-should-do.html
sha256:519fad928845fa0260614c2a469d23e69e6a095cec70fb5a0fba325b8bb03eb5
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| trojanspy.win64.vidar.smcx |
| Open → |
| domain | ag.fls.isb | Open → |
| domain | rti.cargomanbd.com | Open → |
| url | https://github.com/leaked-claude-code/leaked-claude-code | Open → |