logo

Fake software on GitHub and SourceForge distribute Deno RAT 

ID: f2410b2f-78a5-5007-ac6f-8e132c12c792

STIX ID: report--f2410b2f-78a5-5007-ac6f-8e132c12c792

Feed Name: Malwarebytes Blog

Threat Score
78/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

...
...

This report details an active campaign where attackers host fake installers and plugins on GitHub and SourceForge (promoted via compromised YouTube channels) to install Deno and deploy the DinDoor backdoor and a Deno-based RAT capable of full remote control, credential and crypto-wallet theft, and peer-to-peer screen streaming via a hidden Edge instance; the analysis includes infection chains, persistence mechanisms, network C2 endpoints, capabilities, and a list of URLs, domains, and IP IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.