Fake Claude App on GitHub Delivers RevStealer to Harvest Crypto Wallets
Researchers say the trojanized Electron app decrypts a hidden Windows stealer that evades analysis and can use a Polygon smart contract for fallback command-and-control.
Overview
- Morphisec published a technical report on Tuesday, Sept. 1, 2026, showing a GitHub repo named “Claude Opus 5 Free Desktop” distributed a trojanized Electron app that loads RevStealer without showing a user interface.
- The loader runs a series of environment checks, a CAPTCHA-style prompt and language filters to avoid researchers, then attempts to add AppData to Microsoft Defender exclusions before decrypting and launching the native stealer.
- RevStealer searches browser storage, session cookies, Windows Credential Manager, files from 12 password managers and more than 50 crypto wallet apps so operators can hijack accounts or move funds.
- The malware sends encrypted records in a short, non-persistent burst, self-deletes to reduce forensic traces, and can read a fallback server address from a smart contract on the Polygon blockchain if its main server is unavailable.
- Morphisec published indicators of compromise and security outlets amplified the findings, but the malicious GitHub lure remained active and no public law-enforcement disruption tied to this campaign has been reported, raising urgent risks for users who install unverified apps.