This is the story of how I found 10,000 repositories on GitHub that distribute Trojan malware. They are all from different contributors, have different names, and are not forks of other repositories. But they share a common pattern, which is what allowed me to write a script to find
I don’t have the capability to verify at the moment. But I suspect that a case I worked recently was related. A YouTube video was pointing people at a supposed plugin to make Claude free forever. The plugin was actually a Remote Access Trojan (RAT) and credential stealer. The initial loader was hosted on GitHub. The profile was fairly new and only had a couple updates, mostly adding the Trojan and README files.
I don’t have the capability to verify at the moment. But I suspect that a case I worked recently was related. A YouTube video was pointing people at a supposed plugin to make Claude free forever. The plugin was actually a Remote Access Trojan (RAT) and credential stealer. The initial loader was hosted on GitHub. The profile was fairly new and only had a couple updates, mostly adding the Trojan and README files.