Bybit's Security Operations Center has identified a complex malware attack targeting macOS users. The attackers employed SEO poisoning techniques to redirect users searching for the AI development tool "Claude Code" to a fake installation page. This led to a multi-stage attack chain designed to steal credentials, encrypt assets, and gain control over devices. Bybit utilized AI-assisted analysis in their investigation, which also revealed attempts to replace official wallets like Ledger Live and Trezor Suite with trojan versions. Bybit addressed the malicious domains and infrastructure on March 12 and issued detailed protection guidelines on March 20.