Skip to content
PyStoreRAT Malware Targets Developers via GitHub Accounts

PyStoreRAT Malware Targets Developers via GitHub Accounts

First seen 18 Dec 2025, 20:55 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

A new supply chain attack has emerged, utilizing dormant GitHub accounts to spread PyStoreRAT, a previously undocumented malware. This sophisticated attack primarily targets developers by distributing counterfeit developer tools. The incident highlights vulnerabilities in software supply chains and the potential for significant impact on development environments.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track PyStoreRAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed