
Fake "Claude Opus 5 Free Desktop" GitHub Repositories Deliver RevStealer Malware
A fake "Claude Opus 5 Free Desktop" GitHub repository impersonates Anthropic's brand to deliver RevStealer, a credential, browser, and crypto-wallet stealer that self-deletes post-exfiltration. The same lure also appears in game-cheat distributions.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Medium
- Actor Type:
- Cybercriminal
- Geography:
- Global (developer targeting)
- Confidence:
- Confirmed
- MITRE ID:
- T1204, T1555, T1070
- Source:
- Help Net Security / Morphisec
- Read Time:
- 4 min
Executive Summary
A brand-lure malware campaign is impersonating Anthropic's Claude Opus 5 brand on GitHub, offering a fake "Claude Opus 5 Free Desktop" download that delivers RevStealer — a credential, browser, and crypto-wallet stealing malware that self-deletes after exfiltration. The same lure pattern also appears in game-cheat distributions.
This is a commodity lure wearing an AI brand rather than a sophisticated AI-driven attack, but it reflects the growing abuse of trusted AI brand names to lower victim suspicion around downloads.
This is a defensive threat-intelligence analysis of publicly reported research. No exploit code or attack instructions are provided.
Key Findings
- Brand impersonation: Fake GitHub repositories impersonate Anthropic / Claude Opus 5.
- Payload: RevStealer — credential, browser, and crypto-wallet stealer.
- Self-deleting: Malware removes itself post-exfiltration to hinder forensics.
- Secondary lures: Same payload also distributed via game-cheat lures.
- Severity: Commodity lure wearing an AI brand.
Defensive Implications
- Verify download provenance: Users should download AI tools only from official vendor domains, not third-party GitHub repositories using brand names.
- Stealer detection: RevStealer's credential, browser, and crypto-wallet collection warrants endpoint and browser-extension monitoring.
- Anti-forensic awareness: Self-deleting stealers require rapid response and memory/telemetry-based detection rather than disk artifacts.
- Brand-abuse monitoring: Track impersonation of leading AI brands (Anthropic, OpenAI, Google) on GitHub and download portals.
Sources
- Help Net Security / Morphisec (1 Sep 2026)
- Cybersecurity News (secondary)
Defensive research only. No exploit code or attack instructions.
Sources
- 1.Help Net Security — RevStealer malware via Claude Opus 5 GitHubPrimary disclosure
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Citizen Lab Uncovers Pegasus Zero-Click Exploits and NoviSpy Targeting Civil Society in Serbia

Mercenary Spyware Resurgence: Pegasus and NoviSpy Wave Targets Civil Society in Southeastern Europe

