RevStealer malware Claude Opus impersonation targets OBS streaming profiles and credentials
A malicious GitHub repository impersonating Anthropic's Claude AI is distributing RevStealer, a Windows-based information stealer that targets credentials, cryptocurrency wallets, and OBS streaming profiles. The malware employs advanced evasion techniques, including indirect system calls and blockchain-based command-and-control fallback, to compromise user data.
Key Takeaways
- RevStealer specifically targets OBS streaming profiles, cryptocurrency wallets, and credentials from over 50 applications
- The malware uses a fallback command-and-control address hosted on a Polygon blockchain smart contract to maintain persistence
- Morphisec reported that the malicious file was flagged by only one out of 66 antivirus engines during initial testing
- Infection triggers a self-deletion routine and uses indirect system calls to avoid detection by user-mode security hooks
Why It Matters
The targeting of OBS profiles indicates a specific interest in compromising the production environments of streaming professionals and content creators. By gaining access to these profiles, attackers can potentially hijack live broadcasts or steal sensitive stream keys, threatening the integrity of B2B streaming workflows. This incident highlights a growing trend where sophisticated malware leverages AI-themed social engineering to bypass traditional antivirus defenses. As streaming infrastructure becomes increasingly decentralized, the use of blockchain-based command-and-control mechanisms makes these threats harder for enterprise security teams to neutralize. Watch for increased security scrutiny on GitHub repositories offering 'free' versions of proprietary AI tools like Anthropic's Claude.
Additional Context
Anthropic has faced a growing wave of brand impersonation attacks as its Claude AI models gain mainstream adoption. In August 2025, Anthropic published guidance warning users about fake Claude applications and phishing campaigns that exploit the brand's growing recognition, noting that unauthorized third-party apps claiming to offer Claude access have proliferated on GitHub and unofficial app stores. The company's trust and safety team has reported a significant increase in impersonation attempts since Claude 3.5 launched in mid-2025, with attackers leveraging the model's reputation to distribute malware through seemingly legitimate developer tools. This pattern of AI-brand social engineering has become a recognized attack vector across the industry, with multiple security firms tracking similar campaigns targeting OpenAI and Google Gemini users.
The intersection of AI-themed malware and streaming infrastructure represents an emerging threat category that regulatory bodies are beginning to address. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added AI-adjacent supply chain attacks to its Known Exploited Vulnerabilities catalog in early 2026, flagging the risk that compromised developer tools pose to critical media infrastructure. Meanwhile, the European Union's AI Act enforcement provisions, which began phasing in during 2025, require AI providers to implement reasonable measures against unauthorized use of their brand and model outputs, creating potential liability frameworks for companies whose brands are exploited in malware distribution. For streaming platforms and content creators, these regulatory developments signal that security due diligence around AI tooling may soon become a compliance requirement rather than a best practice.
OBS Studio, the open-source broadcasting software targeted by RevStealer, has become a critical piece of professional streaming infrastructure used by millions of content creators and enterprise broadcast teams. OBS Studio surpassed 50 million downloads in 2025, according to the project's official blog, making it one of the most widely deployed video production tools globally. The software's plugin ecosystem, which allows third-party extensions, has previously been exploited; in 2024, security researchers identified malicious OBS plugins distributed through unofficial forums that harvested stream keys and API tokens, a technique that RevStealer's profile-stealing capability appears to build upon. Morphisec, the security firm that discovered the RevStealer campaign, , noting that the attack's use of blockchain-based C2 fallback makes takedown efforts significantly more difficult than traditional malware campaigns.
Read full article at helpnetsecurity.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source