Attackers Hijack GitHub Desktop Repo to Spread Malware via Official Installer
ID: 3e402b24-ee27-5c22-b6e4-649796959b7a
STIX ID: report--3e402b24-ee27-5c22-b6e4-649796959b7a
Feed Name: GBHackers
Threat Score
**GitHub repo-squatting campaign delivers trojanized GitHub Desktop installers via forked README links and malvertising, using a multi-stage .NET loader (HijackLoader) with OpenCL-based sandbox evasion, DLL sideloading, scheduled-task persistence, and exclusions in Defender; campaign active Sep–Oct 2025 and reproducible as of Dec 29, 2025, affecting developers in Europe, Japan and other regions.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
