ThreatsDay Bulletin: Claude Chat Abuse, NastyC2 npm Packages, Device-Code Phishing + 25 More Stories
17:27 · June 18, 2026 · Hacker News AI Section

The internet did not break this week. It got used exactly as designed, which is worse. Searches were siphoned through shady browser add-ons. AI chat links turned into malware delivery paths. macOS attacks ran in memory and left almost nothing behind. Cloud agents looked like helpers until attackers treated them like open shells. Add exposed edge gear, poisoned packages, cash courier scams,
Summary
Recent threat reports detail how attackers are exploiting trusted AI platforms, notably by hijacking Anthropic’s Claude shared-chat feature to distribute the MacSync credential stealer. Campaigns first directed victims through compromised Google Ads for developer tools, then shifted to claude.ai domains themselves, leveraging the site’s reputation to host malicious links. The operation concentrated on the Asia-Pacific region and was active across multiple waves before Anthropic disabled the accounts and conversations involved.
Parallel activity targeted macOS users with fileless infection chains delivered through ClickFix social-engineering lures. Victims were prompted to run clipboard commands that fetched and executed an AppleScript stager entirely in memory, harvesting browser data, keychain items, and cryptocurrency wallets while establishing persistent command-and-control. A separate Russian-speaking actor employed similar techniques against technology and media firms in Asia, North America, and Oceania.
Additional findings highlight risks in AI-assisted developer tooling. Researchers identified local code-execution flaws in the Cline VS Code extension that allowed a malicious repository to bypass approval dialogs and safe-command filters, granting attackers access to credentials and source code on the developer’s machine. Defensive efforts include AWS’s new model-agnostic security agent for continuous vulnerability discovery and remediation across cloud workloads.
The bulletin also notes clusters of deceptive browser extensions that silently reroute search traffic, ongoing phishing operations impersonating travel providers via WhatsApp, and a critical privilege-escalation flaw in Cisco Catalyst SD-WAN components that has been exploited since 2023. Together these incidents illustrate how everyday internet infrastructure and emerging AI services are being repurposed for credential theft and initial access.
Why it matters
The article provides critical threat intelligence regarding the weaponization of AI tools like Claude for malware delivery. This is highly actionable for Dutch security professionals needing to protect enterprise environments from emerging AI-enabled attack vectors.





