Skip to content
Fake GitHub Repositories: Infostealer Instead of Security or Developer Tools

Fake GitHub Repositories: Infostealer Instead of Security or Developer Tools

Heise.De • July 15, 2026

Attackers have created hundreds of GitHub repositories that supposedly originate from well-known companies. A link to the “official page” in the Readme leads to a page of the attackers, which distributes an infostealer.

The malware steals credentials and confidential data from at least 19 web browsers and numerous crypto wallets. Messenger and social media applications, as well as Steam accounts, are also in the attackers' sights.

The attack does not exploit any vulnerabilities but relies on brandjacking and social engineering. The repositories pretend to be from well-known companies in areas such as security, development tools, crypto tools, fintech, and gaming software. The malware runs exclusively on Windows computers.

Security researchers from Arctic Wolf discovered the attack. The trigger was that a fake repository pretended to be from Arctic Wolf. During further investigations, the researchers found that the attackers had created a total of 292 repositories, most of which GitHub has now removed.

However, some repositories are presumably still active, and it is possible that the attackers are creating more fake repositories.

The attack vector is the same every time. For the fake repository for Arctic Wolf, the Markdown file with the Readme (README.md) contained a link to the supposed “official page” of the provider and the software. This link led to a domain of the attackers, which in turn posed as an Arctic Wolf page and offered a package for free download.

The download button bore the text “Download Secure Content,” and numerous badges indicated that the connection was secure and the software had been checked for viruses.

Clicking the button triggered the download of a ZIP file. Apparently, the server distributing the package generated fresh packages every minute with changed ZIP file names and new executable names each time.

In addition to the malware, the archive contained a lot of “bycatch,” which, according to the security researchers' assumption, merely serves to bring the ZIP file to the expected size. The actual malware was contained in two files: gup.exe for loading the file libcurl.dll, which in turn decodes and executes the infostealer in memory.

On September 22 and 23, the heise devSec 2026 will take place. The tenth edition of the conference on secure software development is moving to Marburg this year. The motto remains “Secure software begins before the first line of code”.

According to Arctic Wolf's analysis, the infostealer is a variant of the BoryptGrab discovered by Trend Micro in March , designed to steal numerous data and credentials. However, the malware used for the attack has been reduced to a minimum and, unlike BoryptGrab, does not download further payloads.

The individual modules of the infostealer target different browsers, messengers, crypto wallets, and more.

Finally, the software sends the collected data as a ZIP archive to a Russian server.

After starting, the infostealer runs only once and does not attempt to establish itself as an automatically started process. It also makes no attempts to spread to other systems.

The malware also refrains from cleanup: all collected data and log files of the software remain in a temporary directory that the software does not delete after completing its work.

Further details on the individual modules in the infostealer and the specific IP addresses of the attackers can be found in the Arctic Wolf blog .

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.

Extracted Entities

Attack Types (1)

Malware (1)

Platforms (1)