bleeping-computer · Crawled Jul 14, 2026
Nearly 300 GitHub repos pose as legit software to push malware
1 IoCs
Read original article ↗
AI Summary
A threat actor has created nearly 300 fake GitHub repositories impersonating legitimate software projects to distribute an infostealer malware, primarily targeting credentials, cryptocurrency wallets, and sensitive data from browsers and messaging apps. The malicious repositories redirect users to spoofed download pages that deliver trojanized payloads, including a malicious libcurl.dll that executes the infostealer in memory. The malware, a variant of BoryptGrab, exfiltrates stolen data to a Russia-based C2 server and is designed for maximum data theft in a single execution without establishing persistence or anti-analysis measures.
AI-extracted · verify before operational use
Indicators of Compromise 1 extracted
| Type | Value | Detail |
|---|---|---|
| GitHub Repo | Arctic-Wolf.github.io | Details → |