Fake Claude site installs malware that gives attackers access to your computer
We found a convincing fake site that installs a trojanized Claude app while quietly deploying PlugX malware.
Related Vulnerabilities
- CVE-2026-4432: The YITH WooCommerce Wishlist WordPress plugin before 4.13.0 does not properly validate wishlist own HIGH
- CVE-2026-4158: KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerab HIGH
- CVE-2026-35658: OpenClaw before 2026.3.2 contains a filesystem boundary bypass vulnerability in the image tool that MEDIUM
- CVE-2026-35667: OpenClaw before 2026.3.24 contains an incomplete fix for CVE-2026-27486 where the !stop chat command MEDIUM
- CVE-2026-35660: OpenClaw before 2026.3.23 contains an insufficient access control vulnerability in the Gateway agent HIGH
Related Coverage
Threat Actors