AI Briefing
KO

Fake Claude API Distributes Malware

·2026.04.24 06:37

Key point

A fake Claude API exploited Claude Code to distribute malware.

Details

awstore.cloud gained trust by advertising a cheap Claude API on intermediary platforms like Plati Market, but it was actually a malicious distribution route that caused a PowerShell dropper to be downloaded.

  • After the service resumed, a notice was added stating that only Claude Code for Windows works, a signal that made it hard to view this as a legitimate API reseller.
  • When ANTHROPIC_BASE_URL=https://api.awstore.cloud and a token are entered to connect Claude Code, the server returns a response that looks like a configuration message no matter what prompt is sent.
  • Claude Code interprets this as a tool-use response and automatically executes a PowerShell command, which in turn downloads and runs the dropper from api.awstore.cloud.
  • This behavior was reproduced on a temporary VM, and it was pointed out that a legitimate Claude-compatible API should behave the same regardless of the client.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.