Fake GitHub AI Repos Trick Devs Into Malware

Help Net Security · High sophistication
Last updated August 4, 2026

Researchers say criminals are cloning popular GitHub repositories for AI tools and developer resources, then quietly changing installation instructions to deliver an infostealer. The pages look legitimate (including original contributors), which lures developers into downloading and running a ZIP that launches a malware loader. The campaign has hit organizations across multiple regions, with financial services, banking, and technology most affected.

Key findings

  • Attackers cloned legitimate GitHub repos and “subtly integrate malicious payloads,” often by adding files to a benign-looking folder or changing URLs in installation instructions.
  • Because the repo “appears authentic and the original contributor is listed,” developers are more likely to trust it and run the downloaded content.
  • Malware arrives as a ZIP with two binaries (lua51.dll, compiler.exe), a batch file (Application.bat), and a text file (gc.txt) that gets executed by a renamed LuaJIT interpreter.
  • The loader resolves command-and-control infrastructure at runtime using the Polygon blockchain (EtherHiding), allowing rapid infrastructure changes without updating the malware.
  • Targeting was observed across North America, Asia, and Southern Europe; “financial services, banking, and technology” were among the most affected.

Who’s being targeted

  • Commonly targeted roles: Software Developers, AI/ML Engineers, DevOps/Platform Engineering, IT, Security Awareness/Training, Procurement/Vendor Management (software sourcing).
  • Affected industries: Financial services, Banking, Technology.
  • Attack channels: github, website.
  • Impersonated: A well-known open-source project / legitimate GitHub repository, AI tool brands / AI developer resources hosted on GitHub.

Awareness takeaways

  • Treat GitHub installation steps as untrusted until verified against the official project/vendor channel (especially download links).
  • Do not run ‘installer’ scripts or binaries from a repo just because the page looks authentic, verify releases, maintainers, and file contents first.
  • Be extra cautious with AI-branded “helpers” and “coding assistants,” which are being used as lures to get developers to execute malware.
  • Assume attackers will try to hide infrastructure and evade detection; unusual behavior after running tools (like unexpected network calls or screenshots) should be reported immediately.

Red flags to watch for

  • Installation instructions include a changed/odd download URL compared to the official project
  • A “benign-looking subdirectory” contains executables/scripts (e.g., .bat, .exe, .dll) not expected for the project
  • Repo looks real, but relies on trust signals (e.g., contributor name) instead of verifiable release artifacts
  • Tool claims to be an installer but contains unusual components (e.g., renamed executables like compiler.exe)
  • Windows batch scripts auto-launch interpreters or binaries during installation
  • AI-branded repo offers downloads that do not match official vendor distribution channels
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re on GitHub, grabbing a “Claude / ComfyUI helper tool, quick installer.” Looks legit, original contributor and all. But this is a cloned repo. The attacker quietly swapped the install steps so your “dependencies” are a ZIP with lua51.dll, compiler.exe, Application.bat, and gc.txt that drops an infostealer. Here’s the twist: despite its name, compiler.exe is just a renamed LuaJIT interpreter. When Application.bat runs it, a loader phones home through the Polygon blockchain, pulling fresh malware without ever updating the repo. Next time a GitHub AI helper says “download the latest ZIP and run Application.bat,” stop and compare those install steps against the project’s official releases before you run anything.

Similar attacks

Fake Recruiter Lure Drops NodeRabbit RAT

Fake Recruiter Lure Drops NodeRabbit RAT

Researchers tied Mirage Kitten to a job-recruiting scam that targets developers via LinkedIn and job platforms. Victims are sent a “technical assessment” ZIP file hosted on legitimate cloud storage; running the project silently installs a remote-access trojan (NodeRabbit) that lets attackers…

September 1, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026
OkoBot Tricks Crypto Users Into Running Commands

OkoBot Tricks Crypto Users Into Running Commands

Kaspersky reports an active OkoBot malware campaign targeting Windows users who manage cryptocurrency. Victims are lured via “ClickFix” fake-error pages that trick them into running PowerShell commands, and via GitHub repos posing as legitimate software downloads. The malware then steals wallet…

July 16, 2026
Meta Ads Lure Users Into StreamRat Android Takeover

Meta Ads Lure Users Into StreamRat Android Takeover

Researchers reported a real malvertising campaign where ads on Meta platforms promoted a fake TV-streaming app to Spanish-speaking users, leading them to sideload an Android app. After victims approved a chain of permissions (including Accessibility), the StreamRat trojan could remotely control the…

September 2, 2026
Fake Minecraft Client Sites Still Push WeedHack

Fake Minecraft Client Sites Still Push WeedHack

Researchers report that the WeedHack malware campaign is still infecting people through convincing fake Minecraft client/mod websites, even after its command-and-control server was disrupted. Attackers use SEO poisoning and trusted community platforms (like Discord and Minecraft modding sites) to…

August 25, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026