logo

PyStoreRAT: A New AI-Driven Supply Chain Malware Campaign Targeting IT & OSINT Professionals 

ID: f03064ac-11f2-58df-84e3-c3131d9c0bd8

STIX ID: report--f03064ac-11f2-58df-84e3-c3131d9c0bd8

Feed Name: Morphisec Blog

Threat Score
75/100

Date Published: 2025-12-11

Date Updated: 2026-04-28

...
...

Morphisec Threat Labs describes a coordinated GitHub-based malware campaign dubbed PyStoreRAT in which dormant accounts published polished, AI-generated projects to gain trust and then introduced maintenance commits that deployed a JavaScript/HTA backdoor. PyStoreRAT is a modular, stealthy loader that performs system profiling, adapts execution to evade specific AV products, spreads via removable drives, fetches additional modules from rotating C2 nodes, and delivers payloads including the Rhadamanthys stealer; the report outlines implications for developer ecosystems and defensive controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.