logo

Fake Tools and CDNs Power New “Vibe-Coded” Malware Campaign

ID: b13538e2-0a0f-59b2-963a-ebf21ab11468

STIX ID: report--b13538e2-0a0f-59b2-963a-ebf21ab11468

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-03-19

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

McAfee Labs uncovered a large "vibe-coded" malware campaign distributing over 440 malicious ZIP archives that masquerade as legitimate AI tools, game mods, drivers, and utilities; these trojanized packages sideload a WinUpdateHelper.dll which executes in-memory PowerShell to deploy cryptocurrency miners (and sometimes stealers/RATs), use time-based C2 domains and persistence as a fake Windows service, and employ evasion techniques such as user-agent filtering and Defender exclusion manipulation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.