logo

GitHub Impersonation Deploys Information Stealer

ID: added522-3bf9-5715-a31e-377e78f6e91c

STIX ID: report--added522-3bf9-5715-a31e-377e78f6e91c

Feed Name: Arctic Wolf Blog

Threat Score
75/100

Date Published: 2026-07-02

Date Updated: 2026-07-03

...
...

Arctic Wolf identified and removed a malicious GitHub impersonation campaign that hosted fake vendor repositories (including an Arctic Wolf impersonator) linking to ZIP downloads which contained a trojanized executable that side-loaded a malicious libcurl.dll to deploy the BoryptGrab information-stealer; investigators found nearly 300 similar repositories impersonating multiple security vendors and have published IOCs and enhanced detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.