Think you accidentally shared a Claude Code chat? Follow this practical guide to identify shared conversations, review your privacy settings, and reduce exposure.
Table of Contents
Attackers take advantage of Claude’s legitimate chat to install malware on the device, with the aim of stealing all your files and money.
Cybercriminals are already taking advantage of the rise of large natural language models (LLMs) to carry out social engineering campaigns that can cause a user to compromise all their personal data that they have shared with these chatbots.
An investigation by Zscaler’s threat intelligence team has uncovered a new campaign known as ClaudeFix, which uses legitimate Anthropic LLM chats to silently install malware called MacSync Stealer.
This code is specifically targeted at devices running macOS and allows the attacker to steal login credentials, browser cookies, encryption keys, and even cryptocurrency wallets.
The company does not know exactly what the specific scope of this campaign has been, but it took place in a very specific period, between June 12 and 19 of this year, a strategy that responds to the speed with which the cybercriminals wanted to act so that Anthropic would not notice.
In this sense, the attackers initiated their plan by taking advantage of the legitimate functionality of Claude’s shared chats, thus taking advantage of the victims’ trust from the beginning.
They then sponsored ads on legitimate macOS-related search engines to get users to follow the instructions in these official shared chats. The result was total infection with the Click Fix technique, already known since 2024 in the world of cybersecurity.

The attackers used legitimate links from Claude’s shared chats.
As detailed in Zscaler’s white paper, this campaign did not start as usual, with a malicious link sent to the victim’s email, but was directly indexed in the most common search engines.
The attackers used a technique known as malvertising, a form of SEO poisoning that hires advertising space in the top positions through Google Ads—so their links were among the top positions when a user searched for the term “Claude Mac.”
In other words, it took advantage of reliable links from Claude for users looking for this AI for their Mac device, so they already gained the trust of the victims from the beginning.
From here, security researchers have detailed that 100% of the links came from Google Ads, the multinational’s platform to position the usual sponsored links in first place after a search.
In their specific case, they detected up to 22 unique campaign IDs, so it could be said that there was a well-organized infrastructure to evade blocks in a single account.
Among the terms associated with this malicious campaign, there are the basic ones that would be related to a search for Claude, such as claude, claude ai, claude code, claude mac, ai claude, claude code desktop mac and even a specific version in simplified Chinese.
Once the user clicked on the malicious link, it redirected to an official Claude URL directly hosted on Anthropic’s servers, such as a shared chat, which begins with the domain claude.ai/share/…
A malware that steals absolutely everything without raising suspicion
After gaining the user’s trust, the shared chat used to show Claude’s own instructions for the victim to perform different steps in the terminal of their computer, even being able to copy a malicious script directly.
“By pasting the instruction provided by the deceptive interface, the victim executed a curl-based syntax that transparently downloaded the malicious first-stage script and immediately piped it to the Zsh command interpreter, avoiding storing a file on disk that could be preliminarily analyzed by the local antivirus,” detail in the investigation.
In this way, the user executed a script in the terminal that bypassed any security barrier; When executed, the terminal configuration was modified to be persistent, so that every time the victim opened a new window in the terminal, it was installed and executed again.
Even in later steps, Apple’s security menus were used to take advantage of them and for the victim to grant privilege access to the attacker, eliminating any trace and, of course, accessing all the files on the system.
With full and unlimited access to files, the malware created a temporary directory where all the extracted information was stored: it copied data from Chromium-based web browsers, accessed macOS keychain databases, and allowed you to search for files directly according to extensions, such as confidential documents in pdf, docx, txt, and others. as well as cryptographic keys of cryptocurrencies, their certificates and VPN configurations.
After collecting all the information, MacSync exfiltrated personal data without raising any suspicion by compressing the files into identical 10-megabyte blocks.
Secondly, if there was a failure in any piece of data due to issues derived from the user’s network, it would try to send it again up to 8 more times for each block.
Once the data was exfiltrated, the malware deleted all evidence after the last shipment to the attacker’s server, making it virtually impossible for digital forensics to find their trail.
Logically, Zscaler has warned Anthropic about this new modality, and the latter company has acted quickly to deactivate all these compromised links, so they are no longer available.
However, this does not mean that there will not be campaigns of this type again in the not too distant future, since unfortunately the control over this type of technique is very limited for security teams, even more so when the malware leaves no trace and is practically invisible to security tools.
In any case, as these AI assistants advance unstoppably, an analysis and foresight of these novel techniques becomes more necessary to ensure that a user does not end up giving away all their data and their money—to cybercriminals. Staying informed about the latest security measures and best practices is crucial for users. As technology evolves, so do the tactics employed by cybercriminals, making it essential for individuals and organizations alike to remain vigilant and proactive in safeguarding their information.
FAQ
Q1. How can I check if I accidentally shared a Claude Code chat?
A1. In Claude, go to Settings → Privacy → Manage next to Shared chats. You can review your previously shared chats there.
Q2. What happens when a Claude chat is shared?
A2. A shared chat creates a snapshot containing messages sent before sharing, including artifacts. Anyone with the shared link can view that snapshot.
Q3. Are Claude chats shared automatically?
A3. No. Claude chats are private by default. A chat becomes shareable when you use the Share option to create a shareable link.




