All Topics
All Topics
Technology
Technology
Design
Design
Programming
Programming
Science
Science
News
News
Gaming
Gaming
Entertainment
Entertainment
Business
Business
Finance
Finance
Sports
Sports
Health
Health
Food
Food
Travel
Travel
Art
Art
Music
Music
Books
Books
Education
Education
Politics
Politics
Personal
Personal
No algorithm. No AI slop. No ads. Just RSS. Pro-human. Indie writers. Real journalism. Open web. Chronological. Hand toasted.

Fake ChatGPT and Claude installers on GitHub and SourceForge deliver Deno RAT malware that steals crypto wallets

By

Anamarija Pogorelec

4d ago· 3 min readenNews

Summary

Attackers are distributing counterfeit installers for popular software like ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY on GitHub and SourceForge. These fake downloads deliver a backdoor called DinDoor, which loads a Deno-based remote access Trojan (Deno RAT). Compromised YouTube channels promote the malicious repositories, with videos accumulating over 50,000 views. The malware steals cryptocurrency wallets and hijacks Microsoft Edge for stealth screen streaming. Attackers rotate through GitHub accounts and create multiple repositories per account to evade detection.

Key quotes

· 5 pulled
Attackers are hosting counterfeit installers and plugins on GitHub and SourceForge that pose as widely used software, including ChatGPT, Claude, AutoTune, Kontakt, Ableton Live, and ZENOLOGY.
The downloads deliver a backdoor called DinDoor, which then loads a remote access Trojan built on the Deno JavaScript runtime, according to Malwarebytes.
Compromised YouTube channels push victims toward the malicious repositories.
The videos promoting the fake tools have accumulated more than 50,000 views.
The attackers rotate through GitHub accounts and create multiple repositories per account.
Snippet from the RSS feed
Fake AI installers on GitHub and SourceForge drop Deno RAT malware that steals crypto wallets and hijacks Edge for stealth screen streaming.

You might also wanna read