logo

GitHub’s Dark Side: Unveiling Malware Disguised as Cracks, Hacks, and Crypto Tools

ID: b1bd61cd-b063-52aa-9cce-1efac597aeb9

STIX ID: report--b1bd61cd-b063-52aa-9cce-1efac597aeb9

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2025-01-24

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

McAfee Labs discovered a network of GitHub repositories and associated YouTube links that socially engineer users—particularly children—into downloading game cheats and cracked software which are actually Lumma Stealer variants (and other malware). The report describes the infection chain, technical behavior (searching browsers, harvesting credentials and crypto wallets, connecting to C2 servers), detection/mitigation steps, and provides a list of IoCs including repository URLs, executable hashes, and C2 IP addresses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.