Today's story for every Secure Vibe Coding student Nation-state hackers are now using fake Claude software to install malware. Here is exactly what to watch for. A China-linked espionage group called JadeProx was caught this week running a spear-phishing campaign that impersonated Anthropic Claude software to deliver malware. The targets were technical professionals — government IT staff, developers, researchers. The exact population that uses Claude Code daily. This is not theoretical. It happened. A zip file arrives named something plausible — "Claude_Dev_Update.zip," "ClaudeCode_v4.zip," "AnthropicTool_Setup.exe." It looks like a software update. A developer who uses Claude Code regularly is the target. They download it. They run it. They have installed TriBack Loader, a persistent malware implant that gives the attacker ongoing access to their machine. Your Masterclass community needs to know one thing: legitimate Claude software comes from exactly four places — claude.ai in a browser, the Claude desktop app downloaded from anthropic.com, Claude Code installed via npm install @anthropic-ai/claude-code, and the Claude mobile app from the official app stores. Anywhere else is potentially JadeProx. Share this with your community this week. It is the most direct, actionable security intervention available given today's news. The Hacker News — JadeProx · Group-IB full report 2. Breach Post-Mortem — Course Content Module JadeProx: How an OPSEC Mistake Exposed a Global Espionage Campaign What happened JadeProx is a China-nexus espionage operation that simultaneously targeted a Vietnamese hospital's medical imaging system, Malaysia's Ministry of Foreign Affairs, universities in Hong Kong, and government entities in Honduras and Venezuela. It was exposed not by a sophisticated intelligence operation — but because one operator left a staging server open to the internet with everything visible: bash history, victim paths, phishing packages, post-exploitation tools.