logo

Fake ChatGPT and Claude installers on GitHub are dropping Deno RAT malware

ID: ef5a9306-9521-5fb4-b890-853a5e7fd6f0

STIX ID: report--ef5a9306-9521-5fb4-b890-853a5e7fd6f0

Feed Name: Help Net Security

Threat Score
75/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Anamarija Pogorelec

...
...

Attackers are distributing counterfeit installers and plugins on trusted code-hosting platforms (GitHub, SourceForge), promoted via compromised YouTube channels, to deliver a DinDoor backdoor that loads a Deno-based RAT (Smokest). The toolset executes in memory using legitimately installed tooling (Scoop, WinGet, Deno), establishes persistence, enables remote command execution, file and process control, SOCKS5 tunneling, and includes a stealer targeting 50+ crypto wallet extensions and multiple browsers; it also streams live screens via Edge + WebRTC to evade detection. Malwarebytes observed active repositories that were removed, indicating an ongoing campaign that leverages legitimate platforms and developer tooling to remain under the radar.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.