Cybersecurity researchers at Morphisec have discovered a fake "Claude Opus 5 Free Desktop" application distributed via GitHub that installs malware designed to steal cryptocurrency wallet data and other sensitive information.
The malicious application lures users by offering free access to a paid AI model. Once installed, it deploys an infostealer called Revstealer that targets cryptocurrency wallets including Atomic, Armory, Cake Wallet, Sparrow, Wasabi, Ledger Wallet, Trezor Suite, and Electrum. The malware also collects browser data, password manager files, and VPN configurations.
How the Attack Works
Revstealer copies wallet files and related configuration data without attempting to decrypt them directly. The stolen encrypted wallet material is then compressed and uploaded for further processing. The malware can protect itself from detection and has the ability to delete itself from infected systems.
The effectiveness of the attack depends on wallet security practices. If a wallet uses weak passphrases, reused credentials, or passwords compromised through other means, attackers may gain access to funds. One documented case showed a user whose device was infected after downloading what appeared to be legitimate software from GitHub, with their security software failing to initially detect the malicious executable. The infection subsequently led to compromises of multiple online accounts.
Timing and Social Engineering Risk
Researchers note that the fraudulent Claude app demonstrates how demand for AI tools has become a significant social engineering vector. The release of Fable 5.1 and Mythos 5.1 models on September 1 may create additional opportunities for scammers. While Fable 5.1 is generally available, Mythos 5.1 access is restricted to Anthropic's trusted programs, making it an attractive target for scammers offering fake "exclusive access."


