Cybersecurity researchers say attackers are using fake Claude desktop applications to spread malware that can harvest cryptocurrency wallet data, browser information, password manager contents and VPN configurations from Windows systems.

The lure centers on a GitHub-hosted app presented as “Claude Opus 5 Free Desktop,” promoted as a free way to access a paid AI model. The warning comes as newer Claude-related model names including Fable 5.1 and Mythos 5.1 are being used in social engineering bait.

GitHub lure used to deliver an infostealer

According to the reported findings, the malicious app is disguised as a desktop version of Claude and pitched as a no-cost alternative to a paid service. Once installed on Windows, it deploys an infostealer designed to collect sensitive local data and prepare it for exfiltration.

The malware does not appear to unlock wallets at this stage. Instead, wallet files are copied in their existing form and may be compressed before being uploaded, indicating that the immediate goal is theft of data that can later be abused if other weaknesses are present.

Crypto wallet software is a primary target

The campaign specifically targets a range of wallet applications. Named examples include Atomic, Armory, Cake Wallet, Sparrow, Wasabi, Ledger Wallet, Trezor Suite and Electrum, along with other crypto wallet software.

Researchers said the danger depends partly on what else the attacker can obtain. If a victim uses a weak wallet passphrase, or if credentials are also taken from a password manager, stolen wallet files could become enough to put funds at risk.

The malware reaches beyond wallets

The reported data theft is not limited to cryptocurrency storage. Browser data, password managers and VPN configuration files are also among the targets, broadening the potential impact of a single infection.

The source article notes that online accounts such as Microsoft and EA accounts could also be compromised through the same credential-theft process. That example underscores how an infostealer can turn one deceptive software install into access across multiple services.

Researchers warn of stealth and social engineering

The malware, identified in the report as Revstealer, is described as capable of protecting itself from detection and even deleting itself. Those traits can make investigation and remediation more difficult after a victim has already run the fake installer.

Researchers said the broader risk remains social engineering. Attackers may continue to exploit interest in newly released Claude-branded models, including Fable 5.1 and Mythos 5.1, by offering supposedly free access and persuading users to install malicious desktop software.

What is confirmed so far

The confirmed reporting centers on a fake Claude app distributed through GitHub and a Windows infostealer aimed at wallet files and other sensitive data. The article does not say that the malware directly decrypts wallets or extracts seed phrases during the initial theft stage.

For now, the clearest next step highlighted by the report is continued caution around unofficial AI desktop downloads, especially offers framed as free access to paid models. The main risk described is not the AI branding itself, but the trust it can create when attackers package malware as a desirable app.

Source: news.bitcoin.com