A Malicious Published Claude Artifact Is Ranking on Google for Claude Code Install Queries and Dropping a macOS Infostealer
r/ClaudeAI·high signal
A user reported on r/ClaudeAI that a first-page Google result for how to install Claude Code was a published Claude artifact hosted on a legitimate Anthropic domain, styled to look like Anthropic's install docs, serving a `curl ... | bash` command. Running it triggered a macOS password prompt and installed persistent launch agents requesting further access; the user wiped the disk. The post hit 170 upvotes and the author declined to link the artifact to avoid driving traffic. The attack surface here is the artifact publishing feature itself: a trusted first-party domain laundering an attacker-controlled install script.