Fake ChatGPT and Claude installers on GitHub and SourceForge deliver Deno RAT malware that steals crypto wallets
By
Anamarija Pogorelec
Crusty in the right places. Worth the chew.
Summary
Attackers are distributing counterfeit installers for popular software like ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY on GitHub and SourceForge. These fake downloads deliver a backdoor called DinDoor, which loads a Deno-based remote access Trojan (Deno RAT). Compromised YouTube channels promote the malicious repositories, with videos accumulating over 50,000 views. The malware steals cryptocurrency wallets and hijacks Microsoft Edge for stealth screen streaming. Attackers rotate through GitHub accounts and create multiple repositories per account to evade detection.
Key quotes
· 5 pulledAttackers are hosting counterfeit installers and plugins on GitHub and SourceForge that pose as widely used software, including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY.
The downloads deliver a backdoor called DinDoor, which then loads a remote access Trojan built on the Deno JavaScript runtime, according to Malwarebytes.
Compromised YouTube channels push victims toward the malicious repositories.
The videos promoting the fake tools have accumulated more than 50,000 views.
The attackers rotate through GitHub accounts and create multiple repositories per account.
You might also wanna read
Klarrio Uncovers Large-Scale Malware Network on GitHub
Klarrio discovered a large-scale malware network on GitHub through the research of their CTO, Bruno De Bus, exposing attempts to install mal
Nx Build Kit Security Breach: Malware Steals Wallets and Credentials via GitHub Repositories
A security breach has been discovered in the popular Nx build kit where malicious post-install commands create unauthorized repositories nam
North Korean Hackers Exploit Visual Studio Code to Deploy Backdoor Malware via Git Repositories
Jamf Threat Labs has identified North Korean threat actors expanding their abuse of Microsoft Visual Studio Code to deploy backdoor malware.
JDownloader website hacked, served malware to Windows and Linux users for over a day
The JDownloader website was compromised by attackers who replaced legitimate download files with malware for over a day, targeting Windows a
Fake 7-Zip Website Distributes Malware That Turns Computers into Proxy Nodes
A convincing fake website impersonating the legitimate 7-Zip archiver has been distributing trojanized installers that covertly turn victims
