Claude Builder Brief

Claude Code Security Threats: Fake Installers and CI/CD Secret Leak; New Enterprise Security Guide Published; Axonius Integration Addresses Shadow AI; Practical Security Setup with Auth0; Claude Code v2.1.175 Adds Model Allowlist

Claude Code Security Threats: Fake Installers and CI/CD Secret Leak; New Enterprise Security Guide Published; Axonius Integration Addresses Shadow AI; Practical Security Setup with Auth0; Claude Code v2.1.175 Adds Model Allowlist

Key Questions

What security threats target Claude Code users?

Fake Claude Code installers on 32 sites via Google Ads deliver ACRStealer malware. Additional fake installers use Google Sites in ClickFix campaigns, and a patched GitHub Action vulnerability could leak CI/CD secrets.

What security updates were added to Claude Code?

Version v2.1.175 introduced a hard model allowlist for enterprise admins. Earlier versions v2.1.166-168 included security fixes, and users must verify sources and update promptly.

How are enterprises addressing shadow AI with Claude?

Axonius integrated with the Claude Compliance API to manage shadow AI risks. A practical security setup guide using Auth0 was also published for builders.

Active supply-chain attacks: fake Claude Code installers on 32 live sites via Google Ads deliver ACRStealer. New vector: fake installers via Google Sites (ClickFix campaign). Microsoft disclosed Claude Code GitHub Action Read tool could leak CI/CD secrets; patched. Claude Code v2.1.166-168 adds security fixes. v2.1.175 adds hard model allowlist for enterprise admins. Axonius integrates with Claude Compliance API. Practical security setup guide with Auth0 published. Builders must verify installation sources and update to latest version.

Sources (1)
Updated Jun 19, 2026
What security threats target Claude Code users? - Claude Builder Brief | NBot | nbot.ai