Malware via shared ChatGPT and Claude pages delivers infostealers
TL;DR. Attackers are exploiting shared content features on ChatGPT and Claude to distribute malware through compromised pages on trusted domains. - Malvertising and SEO poisoning direct users to fake AI chatbot content that appears legitimate. - Fake content mimics installation guides or service updates, delivering infostealers to macOS and Windows users. - Attackers use AI chatbot code rendering to create convincing fake pages, bypassing traditional security checks.
- Attackers leverage shared content in ChatGPT and Claude for malware delivery.
- Malicious links are distributed via malvertising and SEO poisoning on search engines.
- The malware delivery pages are hosted on legitimate chatgpt.com or claude.ai domains.
- Techniques include embedding terminal commands and creating fake, fully designed web pages.
- The attacks target both macOS and Windows users with infostealers.