logo

Attackers Hijack GitHub Desktop Repo to Spread Malware via Official Installer

ID: 3e402b24-ee27-5c22-b6e4-649796959b7a

STIX ID: report--3e402b24-ee27-5c22-b6e4-649796959b7a

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**GitHub repo-squatting campaign delivers trojanized GitHub Desktop installers via forked README links and malvertising, using a multi-stage .NET loader (HijackLoader) with OpenCL-based sandbox evasion, DLL sideloading, scheduled-task persistence, and exclusions in Defender; campaign active Sep–Oct 2025 and reproducible as of Dec 29, 2025, affecting developers in Europe, Japan and other regions.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.