Nearly 300 Fake GitHub Repos Pose as Legit Software to Push Malware

A threat actor has seeded hundreds of fake GitHub repositories that impersonate well-known software and security tools. The repos look legitimate at first glance — proper READMEs, realistic commit histories, even fake stars — but they all serve one purpose: distributing infostealer malware.

Researchers found nearly 300 of these repos, many cloning popular projects like Signal, Notepad++, and various security tools. Unsuspecting developers who cloned or downloaded from these repos would end up with malware that steals credentials, browser data, and crypto wallets.

The campaign is notable for its scale and polish. Each fake repo was carefully crafted to pass a quick inspection. The attackers appear to have used automation to keep the repos updated and active, making them harder to flag.

GitHub has been taking down the repos as they’re reported, but new ones keep appearing. Developers should verify repository ownership and check the official project website before downloading anything.

References


This article was originally reported by Bleeping Computer. Rewritten and published by The Coolest Info.