Fake Gemini and Claude Code Sites Spread Infostealers Through SEO Poisoning
Cybercriminals are weaponising developer trust in AI tooling — and Google's own search results are doing the heavy lifting.
Written by OutOfToken AI
June 4, 2026 · 4 min read · Synthesized from reporting by Infosecurity Magazine · How this works
Security researchers at EclecticIQ have exposed a sophisticated malware campaign targeting software developers in the US and UK through counterfeit websites impersonating Google's Gemini CLI and Anthropic's Claude Code. The attackers are exploiting SEO poisoning to surface fraudulent installation pages at the top of search results, turning routine developer curiosity about cutting-edge AI tools into a direct pipeline for credential theft. Once installed, the trojanised packages vacuum up everything from collaboration platform authentication tokens to cryptocurrency wallet data.
The SEO Trap
SEO poisoning is not a new tactic, but applying it to AI developer tooling represents a calculated evolution. Threat actors construct convincing clone sites that mirror the branding, documentation structure, and download flows of legitimate Gemini and Claude Code properties. By aggressively optimising these pages for high-intent search queries — the kind a developer would type when first exploring a new AI coding assistant — attackers push their malicious pages into competitive ranking positions on Google. The result is a trap that requires no phishing email, no social engineering DM, and no compromised supply chain: the victim simply searches, clicks, and installs.
Windows in the Crosshairs
The infostealer payloads delivered through these fake installers are purpose-built for Windows environments, consistent with the operating system's dominance in enterprise developer workstations. Once executed, the malware conducts a systematic sweep of the host machine: harvesting saved browser credentials, extracting session cookies and OAuth tokens from collaboration tools like Slack and Microsoft Teams, and probing for locally stored cryptocurrency wallet files and private keys. The breadth of the collection scope suggests threat actors interested in both immediate financial gain through crypto theft and longer-term corporate access via stolen authentication material — a dual-payload strategy that maximises return on a single infection.
"The payload doesn't just steal passwords — it harvests collaboration authentication keys, turning a single developer's compromised machine into a potential entry point for an entire organisation's internal infrastructure."
Why Developers Are the Prize
Targeting developers is a high-leverage move. A compromised developer workstation typically sits at the intersection of source code repositories, cloud infrastructure credentials, internal API keys, and CI/CD pipeline access. Stealing a developer's tokens doesn't just expose their own data — it can cascade into production environments, customer databases, and intellectual property. The geographic focus on the US and UK further narrows the targeting to markets with high concentrations of well-resourced technology companies, where a single successful intrusion carries outsized downstream value. EclecticIQ assessed the campaign's geographic targeting as deliberate, not incidental, pointing to a threat actor with clear strategic intent rather than opportunistic mass distribution.
As AI coding assistants embed themselves deeper into developer workflows, the attack surface around their tooling will only grow more attractive. Gemini CLI and Claude Code are early targets precisely because they're new enough that developers are still establishing where to find them and what legitimate installers look like — an ambiguity that threat actors are actively exploiting. Security teams need to treat AI tool adoption as a new category of supply chain risk, pushing verified installation sources through internal documentation before developers go searching on their own. In the meantime, the safest assumption is that any AI tooling found via organic search deserves the same scrutiny as an unsolicited email attachment.
Editorial Note
Infosecurity Magazine is a reputable cybersecurity publication with established credibility. SEO poisoning campaigns targeting popular AI tools (Gemini, Claude) through fake sites are consistent with known threat patterns documented by security researchers. The claim about infostealer payloads targeting authentication keys and crypto wallets aligns with documented malware capabilities and motivations.
Claim Tracker
AI-assessed
No independent confirmation or EclecticIQ publication link provided in excerpt
Plausible but specific instances not documented in provided text
Described as payload capability but no technical samples or forensic evidence shown
Method described but no specific search queries, ranking positions, or timeline provided
Comparative claim about attack vector sophistication lacking supporting evidence
Ask AI about this story
// discussion
sign in to join the discussion