Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users with AMOS Stealer

Two significant threat campaigns from March 2026, one abusing Microsoft’s OAuth authentication flow to silently hijack enterprise accounts, and another deploying the AMOS infostealer against macOS users who work with AI development tools like Claude Code. The EvilTokens campaign represents a significant evolution in phishing tactics because it completely bypasses the need to steal passwords. […]

The post Hackers Used EvilTokens, ClickFix Campaign to Attack Claude Code Users with AMOS Stealer appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: