Malicious Claude Artifact Impersonates Official Install Docs to Deliver macOS Infostealer
August 20, 2026
A published Claude artifact hosted on an official Anthropic domain has been used to serve a malicious curl-to-bash script. The script installs a macOS infostealer via persistent launch agents, targeting users searching for Claude Code installation instructions.
HOW THIS AFFECTS YOU
●
builderYou must verify the content of any scripts provided in official-looking artifacts before execution.
●
policyThis highlights a significant supply-chain risk involving legitimate platform features being used for social engineering.