The base64 instructions shown in the shared Claude chat download an encoded shell script from domains such as: In variant seen by Albayrak [VirusTotal]: hxxp://customroofingcontractors[.]com/curl/b42a0ed9d1ecb72e42d6034502c304845d98805481d99cea4e259359f9ab206e
In variant seen by BleepingComputer [VirusTotal]: hxxps://bernasibutuwqu2[.]com/debug/loader.sh?build=a39427f9d5bfda11277f1a58c89b7c2d The 'loader.sh' (served by the second link above) is another set of Gunzip-compressed shell instructions: Base64 code retrieves first stage 'loader.sh' payload
(BleepingComputer) This compressed shell