PSA: a malicious published Claude artifact is ranking on Google for Claude Code install queries — it installed a macOS infostealer on my Mac
Today I searched for how to install Claude Code. A first-page Google result looked exactly like Anthropic’s install docs. It was a published Claude artifact, hosted on a legitimate Anthropic domain, so nothing about the URL looked wrong at first glance. It had a curl ... | bash command. I ran it. It’s similar enough to the process I was used to. The script started a macOS password prompt right after. Since it came from an official url i didn’t think too much of it. After a few seconds i turned off wifi when it hit me what I had done. After a few hours of changing passwords, turning off every possible device connection, and reviewing every setting in my accounts, I started looking at the laptop again. The script installed a few persistent launch agents and is asking me for accesses. I decided to clean up the disk and start things over. I have added a screenshot in the comments of the artifact, i think linking it could cause more traffic and higher risk of showing up. EDIT: guys i googled how to install it, opened the first thing that appeared from an official website, and used it. Its not like I tried some weird way of installation. No one has their guard up all the time. Sure it was preventable but if it got me it will get other people as well. I will not link the artifact as that will make it cause more traction but i added the screenshot