# Fake Claude Code installers: keep keys out of agent-readable paths

Your coding agent is only as trustworthy as the binary that started it and the secrets it can read. In September 2026, Anthropic’s threat intelligence report documented a criminal AI supply chain that spoofed popular AI harnesses — including Claude Code — so victims installed credential harvesters instead of the real client. Stolen API keys and session tokens then became loot, free attack compute, and cover under the legitimate owner’s identity. The same report warns that discounted “intermediary” AI access that routes traffic through unknown middlemen is a risk, not a bargain.

---

*This is an excerpt. Read the full post at [otf-kit.dev/blog/anthropic-fake-claude-code-installers](https://otf-kit.dev/blog/anthropic-fake-claude-code-installers) — full-stack kits your AI coding agent can actually ship to production. [Browse the kits →](https://otf-kit.dev)*
