Gate News, March 11 — GoPlus issued a security alert stating that attackers are using Google search ads to distribute malware that perfectly clones the official Claude Code installation page at a pixel level. This malware can steal user passwords, cookies, session tokens, crypto wallet credentials, and system information. GoPlus recommends users take the following precautions: identify ad labels in search results and carefully verify URL differences from the official website; verify installation methods through official documentation, social media, or GitHub repositories via multiple channels; avoid executing unfamiliar commands directly and analyze command behavior before running; install security plugins to intercept phishing links, risk signatures, authorizations, and transactions in real time.