logo

Attackers Hijacking Official GitHub Desktop Repository to Distribute Malware as Official Installer

ID: 5dbca68f-1591-568b-84eb-be1af31857c3

STIX ID: report--5dbca68f-1591-568b-84eb-be1af31857c3

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-01-27

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Cybercriminals used repo squatting and sponsored ads to distribute a malicious Windows installer (e.g., GitHubDesktopSetup-x64.exe) that impersonates GitHub Desktop and other apps; the loader conceals a .NET payload in the file overlay and leverages OpenCL GPU checks (GPUGate) and code misdirection to evade sandbox/VM analysis, with infections observed primarily in Europe and the EEA and later spreading to Japan.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.