GitHub was turned into a showcase for malware, and the victim does not need to open a suspicious archive or go to a fake site. Avyukt Security researchers have discovered Operation RepoGhost, in which attackers have created dozens of plausible repositories with tools for AI, cybersecurity, cryptocurrencies, and vulnerability search. The launch of the downloaded project simultaneously launched a hidden chain of infection.
The investigation began with the search for a working exploit for CVE-2026-41940. Among the results was the GitHub repository, which looked like a full-fledged PoC, contained detailed documentation and managed to collect 313 stars and 39 forks. The exploit itself had no relationship to vulnerability. Most of the code was associated with a foreign project claude-engineer, which was probably added for plausibility.
At the beginning of the Python script, there was a real load. The code ran the Microsoft App-V scriptrunner.exe system component, through it discreetly opened PowerShell and downloaded the next script with Pastebin. Then the computer got an executable file on Go, which downloaded the obfused build. NET directly into memory and connected to the command server.
The final malware worked as an infostiler. She searched for saved browser sessions and credentials, Discord tokens, active sessions of Telegram and Steam, as well as data of cryptocurrency wallets. Before stealing information, the program checked the Windows language. When the locale was detected, the ru-RU performance was stopped.
The history of GitHub-committees showed that the infrastructure changed along with malware. The earliest activity dates back to November 2025, when operators were spreading CountLoader to Windows. In January 2026, repositories with NovaStealer for macOS appeared, and by June, criminals had focused on their own Windows data thief, written on Go.
According to the common fragments of the code, the history of commits and infrastructure, the researchers associated with RepoGhost 52 repository. Among the baits were fake Claude and Sora projects, OSINT tools, React2Shell scanners, cryptocurrency utilities, trading bots and bogus PoCs for known vulnerabilities.
Avyukt Security links the campaign with Russian-speaking hackers with moderate or high confidence. The researchers rely primarily on the deliberate refusal of the malicious program to work in Russian-language Windows and on the use of the CountLoader and NovaStealer families, which previously met in the Russian-speaking criminal environment. The authors emphasize that none of the signs in itself allows to establish the origin of operators.
The investigation began with the search for a working exploit for CVE-2026-41940. Among the results was the GitHub repository, which looked like a full-fledged PoC, contained detailed documentation and managed to collect 313 stars and 39 forks. The exploit itself had no relationship to vulnerability. Most of the code was associated with a foreign project claude-engineer, which was probably added for plausibility.
At the beginning of the Python script, there was a real load. The code ran the Microsoft App-V scriptrunner.exe system component, through it discreetly opened PowerShell and downloaded the next script with Pastebin. Then the computer got an executable file on Go, which downloaded the obfused build. NET directly into memory and connected to the command server.
The final malware worked as an infostiler. She searched for saved browser sessions and credentials, Discord tokens, active sessions of Telegram and Steam, as well as data of cryptocurrency wallets. Before stealing information, the program checked the Windows language. When the locale was detected, the ru-RU performance was stopped.
The history of GitHub-committees showed that the infrastructure changed along with malware. The earliest activity dates back to November 2025, when operators were spreading CountLoader to Windows. In January 2026, repositories with NovaStealer for macOS appeared, and by June, criminals had focused on their own Windows data thief, written on Go.
According to the common fragments of the code, the history of commits and infrastructure, the researchers associated with RepoGhost 52 repository. Among the baits were fake Claude and Sora projects, OSINT tools, React2Shell scanners, cryptocurrency utilities, trading bots and bogus PoCs for known vulnerabilities.
Avyukt Security links the campaign with Russian-speaking hackers with moderate or high confidence. The researchers rely primarily on the deliberate refusal of the malicious program to work in Russian-language Windows and on the use of the CountLoader and NovaStealer families, which previously met in the Russian-speaking criminal environment. The authors emphasize that none of the signs in itself allows to establish the origin of operators.