Fake AI tool GitHub infostealer campaign

Posted under: Online Security
Date: 2026-08-04
fake AI tool GitHub infostealer campaign | Justo Global

A large malware campaign is exploiting developers' interest in AI tools by cloning trusted GitHub repositories and embedding malicious code inside fake downloads. Researchers linked the operation to the TroyDens lure factory, which targets users searching for coding assistants, Claude utilities, ComfyUI projects, Python security resources and Rust frameworks. Victims download ZIP archives containing a batch file, a renamed LuaJIT interpreter and an obfuscated script that launches the two-stage SmartLoader malware. Once executed, the malware collects system details, IP address, location information and screenshots before retrieving its command-and-control server by querying a Polygon blockchain smart contract. This blockchain-based lookup allows attackers to change infrastructure without updating the malware itself. The campaign ultimately delivers a Malware-as-a-Service infostealer capable of stealing enterprise credentials.

Read more at: cybersecuritynews.com

Related videos

Fake AI tool GitHub infostealer campaign

Posted under: Online Security
Date: 2026-08-04
fake AI tool GitHub infostealer campaign | Justo Global

A large malware campaign is exploiting developers' interest in AI tools by cloning trusted GitHub repositories and embedding malicious code inside fake downloads. Researchers linked the operation to the TroyDens lure factory, which targets users searching for coding assistants, Claude utilities, ComfyUI projects, Python security resources and Rust frameworks. Victims download ZIP archives containing a batch file, a renamed LuaJIT interpreter and an obfuscated script that launches the two-stage SmartLoader malware. Once executed, the malware collects system details, IP address, location information and screenshots before retrieving its command-and-control server by querying a Polygon blockchain smart contract. This blockchain-based lookup allows attackers to change infrastructure without updating the malware itself. The campaign ultimately delivers a Malware-as-a-Service infostealer capable of stealing enterprise credentials.

Read more at: cybersecuritynews.com
Open-source: The power of collective information

Open-source: The power of collective information

Open-source: The power of collective infor...

Elevate Your Sales Using Managed Services - Don't Miss Out!

Elevate Your Sales Using Managed Services - Don't Miss Out!

Elevate Your Sales Using Managed Services ...

How CRM Transforms Customer Relationships? #crm #technology #technews #business #businessautomation

How CRM Transforms Customer Relationships? #crm #technology ...

How CRM Transforms Customer Relationships?...