Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning

Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning

Cybercriminals are weaponising developer trust in AI tooling — and Google's own search results are doing the heavy lifting.

Written by OutOfToken AI

June 4, 2026 · 4 min read · Synthesized from reporting by Infosecurity Magazine · How this works

AI Likely Accurate · 8/10

Security researchers at EclecticIQ have exposed a sophisticated malware campaign targeting software developers in the US and UK through counterfeit websites impersonating Google's Gemini CLI and Anthropic's Claude Code. The attackers are exploiting SEO poisoning to surface fraudulent installation pages at the top of search results, turning routine developer curiosity about cutting-edge AI tools into a direct pipeline for credential theft. Once installed, the trojanised packages vacuum up everything from collaboration platform authentication tokens to cryptocurrency wallet data.

The SEO Trap

SEO poisoning is not a new tactic, but applying it to AI developer tooling represents a calculated evolution. Threat actors construct convincing clone sites that mirror the branding, documentation structure, and download flows of legitimate Gemini and Claude Code properties. By aggressively optimising these pages for high-intent search queries — the kind a developer would type when first exploring a new AI coding assistant — attackers push their malicious pages into competitive ranking positions on Google. The result is a trap that requires no phishing email, no social engineering DM, and no compromised supply chain: the victim simply searches, clicks, and installs.

Windows in the Crosshairs

The infostealer payloads delivered through these fake installers are purpose-built for Windows environments, consistent with the operating system's dominance in enterprise developer workstations. Once executed, the malware conducts a systematic sweep of the host machine: harvesting saved browser credentials, extracting session cookies and OAuth tokens from collaboration tools like Slack and Microsoft Teams, and probing for locally stored cryptocurrency wallet files and private keys. The breadth of the collection scope suggests threat actors interested in both immediate financial gain through crypto theft and longer-term corporate access via stolen authentication material — a dual-payload strategy that maximises return on a single infection.

"The payload doesn't just steal passwords — it harvests collaboration authentication keys, turning a single developer's compromised machine into a potential entry point for an entire organisation's internal infrastructure."

Why Developers Are the Prize

Targeting developers is a high-leverage move. A compromised developer workstation typically sits at the intersection of source code repositories, cloud infrastructure credentials, internal API keys, and CI/CD pipeline access. Stealing a developer's tokens doesn't just expose their own data — it can cascade into production environments, customer databases, and intellectual property. The geographic focus on the US and UK further narrows the targeting to markets with high concentrations of well-resourced technology companies, where a single successful intrusion carries outsized downstream value. EclecticIQ assessed the campaign's geographic targeting as deliberate, not incidental, pointing to a threat actor with clear strategic intent rather than opportunistic mass distribution.

As AI coding assistants embed themselves deeper into developer workflows, the attack surface around their tooling will only grow more attractive. Gemini CLI and Claude Code are early targets precisely because they're new enough that developers are still establishing where to find them and what legitimate installers look like — an ambiguity that threat actors are actively exploiting. Security teams need to treat AI tool adoption as a new category of supply chain risk, pushing verified installation sources through internal documentation before developers go searching on their own. In the meantime, the safest assumption is that any AI tooling found via organic search deserves the same scrutiny as an unsolicited email attachment.

Editorial Note

Infosecurity Magazine is a reputable cybersecurity publication with established credibility. SEO poisoning campaigns targeting popular AI tools (Gemini, Claude) through fake sites are consistent with known threat patterns documented by security researchers. The claim about infostealer payloads targeting authentication keys and crypto wallets aligns with documented malware capabilities and motivations.

Claim Tracker

AI-assessed

UnverifiedEclecticIQ security researchers exposed a malware campaign targeting developers in US and UK

No independent confirmation or EclecticIQ publication link provided in excerpt

UnverifiedCounterfeit sites impersonate Google's Gemini CLI and Anthropic's Claude Code

Plausible but specific instances not documented in provided text

UnverifiedInfostealers collect collaboration authentication keys and cryptocurrency wallet data

Described as payload capability but no technical samples or forensic evidence shown

UnverifiedAttackers use SEO poisoning to rank malicious pages high in Google search results

Method described but no specific search queries, ranking positions, or timeline provided

UnverifiedAttack requires no phishing email, social engineering DM, or compromised supply chain

Comparative claim about attack vector sophistication lacking supporting evidence

Ask AI about this story

// discussion

sign in to join the discussion