đ„ Claude Code Leak: 512k Lines Weaponised, 10k US Dev Rigs Now Proxy Zombies
TL;DR
- Claude Code source code leaked, triggering trojanized repos with Vidar and GhostSocks infostealers targeting 10,000+ downloads
- Microsoft integrates Sysmon into Windows 11 with AI-powered threat detection
- Russia's internet blocking attempts trigger nationwide banking failure, disrupting payments and Telegram services
đ„ Claude Code Leak: 512k Lines Weaponised, 10k US Dev Rigs Now Proxy Zombies
512k lines of Claude just dropped like a drunk USB in the clubâ59MB of TS treasure map baited 10k+ devs to snort Vidar & GhostSocks straight up their CI! đ§š Corp âoopsâ â your rigs mine coin for rando socks. Whoâs reinstalling Windows tonight, USA coders?
Anthropicâs crown-jewel source-mapâ512 k lines, 59 MB of TypeScriptâwas âoops-droppedâ on GitHub last Monday. By Tuesday, two fork-farms were slinging a .7z labeled âLeaked Claude Codeâ like it was Black-Friday firmware. One click â Rust dropper â Vidar v18.7 vacuums passwords, cookies, seed phrases; GhostSocks flips your laptop into a $0.30-per-Gb SOCKS sock-puppet. Ten-thousand-plus devs already bit; Zscaler tallies 793 malicious forks still smirking behind DMCA takedowns that missed the party.
How the heist works (spoiler: itâs stupidly simple)
- Source-map ships full CLI logic; no obfuscation, no guardrails.
- Bad actors add one fake âDownload ZIPâ button; GitHub stars snowball (564 and climbing).
- ClaudeCode_x64.exe is just a 1.2 MB Rust wrapper that sideloads two payloads before you can say ânpm audit.â
Impacts (or, why your weekend is now ruined)
Credential Hemorrhage: >10 k endpoints coughing up AWS keys, crypto seeds, corporate VPN creds â instant underground supermarket.
Proxy Farm: infected boxes join a residential botnet; your ISP bill spikes while someone else streams abuse through your IP.
Reputational Face-Plant: Anthropicâs âhelpful, harmless, honestâ tagline becomes a punch-line on InfoSec Twitter.
Institutional âresponseâ (a.k.a. whack-a-mole)
GitHub nuked ~8 k repos but left 96 forks âfor researchâ; npm yanked poisoned axios 0.14.1 & 0.30.4 yet fresh typosquats pop up hourly. Anthropicâs official advice so far: âPlease donât download leaked code.â Gee, thanks.
SWOT for the rest of us
- Strength: public IOC list dropsâblock ClaudeCode_x64.exe, port 1080 SOCKS.
- Weakness: source-maps still default-on in half the npm universe.
- Opportunity: cheap PR for any vendor selling âsupply-chain sparkle.â
- Threat: next leak wonât need social engineering; CI will auto-clone-and-own itself.
Outlook (set calendar reminders so you can say âtold yaâ)
- This week: fork count 1 k, downloads 20-30 k, fresh fake releases on DirectDownload sites.
- Q2 2026: modular Rust loader goes file-less, targets GitHub Actions runners; expect Fortune-500 âClaude insideâ breaches.
- 2027: regulators mandate source-map sterilization; meanwhile your build pipeline is still sipping from whatever repo has the most stars.
Bottom line: if the codeâs âtoo big to ignore,â itâs too fat to audit. Wrap your own CI in tar, feathers, and offline keysâbecause the next âoopsâ is already queued.
đȘ Sysmon Hardwired in 80 M Win11 US Boxes: 2 % CPU Toll, AI Cop Watches Every Click
đȘ 80 million US PCs just got a built-in snitchâSysmon baked into Win11, AI cop reading every twitch. Thatâs 3â0.3 day rollout, +2 % CPU for the privilege. Your cheat engine already BSODâing, gamer. Still trust the âoptionalâ switch? â whoâs muting Redmond in YOUR taskbar?
Microsoft finally duct-taped Sysmon into Windows 11 (build 26200.8037, March 10). One sysmon âi config.xml later, every Home gamer, broke SMB, and Fortune-500 mothership inherits 30â50 % better anomaly visibilityâwithout the 3-day manual-install hangover. CPU tax? A lazy 2 % at idle; RAM bloat, 15 MBâless than one Chrome tab of doom.
How it works
- Events: process, network, file, registry, driverâSHA-256 hashes included.
- AI risk score: 0-100, only screams when >70; model is a black box, because transparency is so 2020.
- Channel: dumps into
Microsoft-Windows-Sysmon/Operational; your SIEM will drink it like cheap coffee.
Impacts
Home users: suddenly sport telemetry that used to require a CS degree â momâs laptop now snitches on phishing exeâs.
Enterprise: 25 % more endpoint noise headed to Sentinel/CrowdStrike â analysts drown faster, but catch creeps.
Gamers: 0.3 % see anti-cat drivers nuke boot loops â âCompatibility Modeâ registry hack keeps RGB alive.
Timelineâmark your calendar, or donât
- Q3 2026: auto-quarantine switch flips; lateral-movement AI gets revenge.
- Q4 2026: file-hash cloud lookup + Azure AD correlation; expect 12 % fewer false positivesâstill means 88 % bullshit.
- 2027 preview: âSysmon-as-a-Serviceâ lands in Windows 12âbecause why own your logs when you can rent them?
Bottom line
Redmond stuffed a free, open-source bouncer inside the club. Itâs underpaid, overworked, but yoursâno license audit, no CFO tears. Use it, tweak it, drown the logs in cheap storage, and remember: the only thing cheaper than zero cost is the zero damn Microsoft gives about your Sunday uptime.
đ„ 80% Telegram Dead, Banks Bleed $24M: Russiaâs Net Clampdown Hits Moscow
80% of Telegram pings vanishâKremlin says "just a hiccup"đ„ Thatâs 50M VPN junkies cold-turkey, banks barfing $24M in 24h, & babushkas dusting off pagersđ Cash-only Moscow feels 1998 againâexcept now the app they shove down your throat is named MAXđ€Ą Whoâs side-loading freedom tonight?
Russia just rage-quit its own economy. On 3 Apr, the Kremlinâs whitelisting circus throttled Telegram, WhatsApp, Signalâand, bonus round, the banking APIs that actually move money. Result: Sberbank, T-Bank and VTB went dark for 30-45 min, shoving 100 % of retail back to sweaty wads of rubles. Instant damage: 1-2 billion RUB (â $12-24 M) in lost salesâenough to buy every Muscovite a beer, if beer hadnât vanished from card readers.
Payments: Plastic turned plastic-implant â cash-only queues snaking round blocks, counterfeit risk up, liquidity gasping.
Comms: Telegram reach -25 %; military & charity donation channels flatlineâ70-80 % drop in crisis-crowdfunding expected.
Consumer Darwinism: Walkie-talkie sales +27 %, pagers +73 %âbecause nothing screams âmodern economyâ like 1993 hardware.
How the sausage was made
Roskomnadzor flipped its âwhitelistâ switch: only pre-approved IP ranges pass. Anything encrypted and not called âMAXâ (the stateâs sad clone) gets 80 % packet loss. Banks ride the same pipes, so when Telegram bled, their APIs drowned. Meanwhile 50 M VPN junkies hit brick walls; 60 k accounts ghosted in a single afternoon.
Institutional face-plants
- MAX app adoption: <10 %âeven bureaucrats wonât friend it.
- VPN fee proposal: $15/month for 15 GBâturns privacy into a luxury tax.
- International shrug: investors eye the exit; sanctions sharpen.
Short â long arc (brace)
- Q2 2026: Intermittent bank tantrums each time Telegram sneezes; VPN traffic down another 15 %.
- Q3 2026: Full Telegram block probable; MAX limps to 20-30 % share, satisfaction sub-40 %.
- 2027-28: E-commerce hemorrhages 50-100 B RUB yearly; offline comms market stabilizes 2Ă biggerâyour next âstart-upâ might be re-selling fax ribbons.
Hack the pain
Banks: multi-path routing + satellite backupâstop hitching your wagon to censors.
Users: flash-drive-sized mesh firmware, stealth VPN configsâswap âem in cafĂ©s like mixtapes.
Policy voyeurs abroad: sanction the DPI vendors, not just the politburo.
Russia wanted a sovereign net; it built a sovereign net-loss. Every block is a free ad for open techâdownload it while you still can.
In Other News
- Windows 11 Introduces PktMon: Built-In Packet Analyzer for SDN, Containers, and Network Diagnostics
- Perplexity faces $5,200-per-violation lawsuit for sharing user data with Google and Meta without consent
Comments ()