logo

New GitHub Scam Uses Fake “Mods” and “Cracks” to Steal User Data

ID: 9086ccbf-f887-5772-98db-b52632b595d4

STIX ID: report--9086ccbf-f887-5772-98db-b52632b595d4

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2025-02-28

Date Updated: 2026-04-22

Author: Divya

...
...

A research analysis uncovers a widespread campaign using over 1,100 GitHub repositories that masquerade as game modifications and cracked software to distribute the Python-based Redox stealer, which automates credential and cryptocurrency-wallet extraction and exfiltration (via obfuscated Discord webhooks). The report documents social-engineering tactics (topic poisoning, AI-generated READMEs), payload obfuscation (passworded RARs, Anonfiles), technical harvesting modules (browser/Steam/Discord/SQLite scraping, DPAPI-based secrets), active evasion of GitHub detection, and an estimated scale of thousands of victims monthly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.