Fake Claude site installs malware that gives attackers access to your computer
We found a convincing fake site that installs a trojanized Claude app while quietly deploying PlugX malware.
Related Vulnerabilities
- CVE-2026-35621: OpenClaw before 2026.3.24 contains a privilege escalation vulnerability where the /allowlist command HIGH
- CVE-2026-5496: Labcenter Electronics Proteus PDSPRJ File Parsing Type Confusion Remote Code Execution Vulnerability HIGH
- CVE-2026-40100: FastGPT is an AI Agent building platform. Prior to 4.14.10.3, the /api/core/app/mcpTools/runTool end MEDIUM
- CVE-2026-4057: The Download Manager plugin for WordPress is vulnerable to unauthorized modification of data due to MEDIUM
- CVE-2026-35653: OpenClaw before 2026.3.24 contains an incorrect authorization vulnerability in the POST /reset-profi HIGH
Related Coverage
Threat Actors