Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Security

292 fake GitHub repos push a hash-dodging infostealer

Ransomnews Research TeamBy Ransomnews Research TeamJuly 15, 2026Updated:July 18, 2026No Comments4 Mins Read956 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
292 fake GitHub repos push a hash-dodging infostealer, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Arctic Wolf Labs documented a campaign using more than 292 fake GitHub repositories that impersonate security, fintech, crypto, and gaming vendors to deliver a BoryptGrab-lineage infostealer. Repository READMEs route victims through GitHub Pages redirectors to fake download pages serving ZIP files that regenerate roughly every 60 seconds to defeat hash-based detection. A legitimately signed updater then side-loads a trojanized library. The campaign, which began June 26, 2026, abuses GitHub’s trust and search ranking to spread an in-memory credential and wallet stealer.

What is the fake-repo campaign?

The operation weaponizes GitHub’s credibility. A financially motivated actor stood up hundreds of repositories posing as well-known vendors, including a fake page impersonating a major security firm. Each repository’s README links out through GitHub Pages (github.io) redirectors to convincing download pages. The files served there are ZIP archives that the operators regenerate about once a minute, so no two victims necessarily download the same file hash. A validly signed WinGUP updater side-loads a trojanized libcurl library, executing the stealer in memory.

FAKE GITHUB REPOS // DELIVERY CHAIN FAKE REPOREADME lure → github.ioredirector → FAKE DL PAGEZIP rotates~every 60s → SIGNED UPDATERside-loadsbad libcurl.dll → STEALERin memory CAMPAIGN SCALE (Arctic Wolf Labs) 292+fake repos ~78redirector accounts 20distribution domains 11theft modules Targets ~32 wallet brands, 19+ browsers. C2 hosted on Proton66 (Russia). Campaign start: June 26, 2026 | Family: BoryptGrab lineage

Why the 60-second rotation matters

Traditional detection often leans on file hashes: identify a malicious file once, block that hash everywhere. Regenerating the payload roughly every minute breaks that model, because the hash is stale almost as soon as it is catalogued. Combined with a legitimately signed updater carrying the malicious library, the campaign is engineered to slip past both signature checks and reputation systems. This is the same pressure that pushed the wider stealer market toward polymorphism, a trend we track across the top infostealer families of 2026.

What the stealer takes

Arctic Wolf assessed the payload as the BoryptGrab family: an in-memory stealer with 11 theft modules, a wallet-path table covering roughly 32 cryptocurrency wallet brands, and support for more than 19 browsers. Its command-and-control sat on Proton66 infrastructure in Russia. The harvested credentials and session cookies feed the same access economy that fuels ransomware, which is why exposed logins belong in a stealer-log check.

What defenders and developers should do

Treat GitHub search results and READMEs as untrusted delivery surfaces, not as endorsements. Download tools only from a vendor’s verified domain, not from a repository link chain. For defenders, behavior-based detection matters more than hashes here: watch for signed updaters side-loading unexpected libraries and for in-memory credential access. Block the reported distribution domains and C2, and rotate any credentials or wallet keys that may have touched an affected machine.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Frequently asked questions

How does the fake GitHub campaign avoid detection?

It regenerates the malicious ZIP roughly every 60 seconds so file hashes are constantly changing, and it uses a legitimately signed updater to side-load a trojanized library, defeating both hash and signature checks.

What is BoryptGrab?

BoryptGrab is the infostealer family Arctic Wolf attributed to the payload. It runs in memory with 11 theft modules and targets around 32 wallet brands and more than 19 browsers.

How many fake repositories were involved?

Arctic Wolf found more than 292 fake repositories, about 78 redirector accounts, and 20 distribution domains in the campaign, which began June 26, 2026.

Is GitHub itself compromised?

No. The attackers abuse GitHub’s hosting, trust, and search ranking by creating fake repositories and Pages redirectors. The platform is being used as a delivery surface, not breached.

What should I do if I downloaded a tool this way?

Assume credentials, browser sessions, and wallet keys on that machine are compromised. Rotate passwords, revoke sessions, move funds from exposed wallets, and run a full endpoint investigation.

Sources and further reading

  • Arctic Wolf Labs: Fake GitHub repositories deliver BoryptGrab-lineage infostealer
  • Help Net Security: Impersonated brands on GitHub push infostealer (July 15, 2026)
  • Ransomnews: Top infostealer families in 2026
  • Ransomnews Stealercheck: check exposed credentials

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous Article570 flaws, 2 exploited: July Patch Tuesday hits identity
Next Article Coca-Cola’s Fairlife halts US production after ransomware
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Best VirusTotal alternatives 2026: what threat hunters run

August 9, 2026

SOAR vs SIEM 2026: tune before you automate

August 6, 2026

SIEM vs XDR 2026: retention is the deciding factor

August 6, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.