Particle.news
Download on the App Store

Hundreds of Fake GitHub Repos Used to Deliver BoryptGrab Infostealer

Arctic Wolf says search‑optimized impersonation pages keep sending credential and crypto‑theft malware despite many GitHub takedowns.

Overview

  • Arctic Wolf discovered a campaign that began on June 26, 2026, in which an operator created roughly 292 fake GitHub repositories that impersonated security tools, crypto services, developer utilities and more to lure victims to malicious downloads.
  • Each repo hosted a README with a hidden link that redirected users through a *.github.io page to a templated, SEO‑optimized landing page that served a ZIP file with a renamed signed WinGUP updater and a trojanized libcurl.dll.
  • When run, the signed updater side‑loads the malicious libcurl.dll to load a BoryptGrab‑family infostealer in memory that steals passwords, cookies, payment data, data from 19 browsers, data from 32 crypto wallet brands, messaging and gaming session tokens, and files, then exfiltrates the data to a Russia‑hosted C2.
  • GitHub removed many of the reported repositories after Arctic Wolf flagged them, but dozens of GitHub Pages redirectors remained active and the operator continues to spin up new impersonation accounts, making takedowns an incomplete defense.
  • Arctic Wolf published IoCs and a Yara rule and urges anyone who executed a sample to rotate credentials, revoke sessions and wallet keys, and search for the malware’s temporary staging folders that the stealer leaves behind for forensic recovery.