top of page

292 fake GitHub repositories distribute BoryptGrab malware

Arctic Wolf Labs reported that, beginning on June 26, 2026, an unidentified threat actor operated at least 292 GitHub repositories impersonating software brands to distribute a BoryptGrab variant on Windows. The malware targets more than 19 browsers, cryptocurrency wallet data, session tokens, and credentials. The incident is not associated with a specific CVE.

For businesses, the risk extends beyond a single infected workstation. Browser-saved passwords, login cookies, Discord, Telegram, and Steam tokens, as well as data stored in Windows Credential Manager, could become starting points for account takeover, unauthorized access to email, cloud services, or internal systems.

What happened to the fake GitHub repositories?

Arctic Wolf discovered the campaign after a GitHub page impersonating the company itself was used to target customers and users. A broader investigation identified at least 292 organization pages and .github repositories impersonating software vendors, security tools, and various popular projects.

The fake repositories did not directly contain exploit code. Instead, their README files were designed to resemble product landing pages, using download buttons, marketing content, and fake certification badges to redirect users through multiple stages to a server controlled by the attackers.

 292 fake GitHub repositories distribute BoryptGrab malware
 292 fake GitHub repositories distribute BoryptGrab malware

The impersonated categories ranged from cybersecurity tools, financial services, cryptocurrency wallets and exchanges to developer utilities, secure email services, macOS software, and gaming tools. The targeting was opportunistic and primarily relied on search engine traffic rather than focusing on a specific industry.

Businesses that use GitHub in their development workflows can refer to IPSIP Vietnam’s analysis of attack risks involving seemingly legitimate GitHub repositories. The two campaigns use different mechanisms, but both demonstrate that a project’s presence on GitHub does not mean its content or execution instructions have been verified.

What figures stand out in the BoryptGrab campaign?

Arctic Wolf published several indicators showing that the distribution infrastructure was designed to operate at scale. However, the number of fake repositories does not represent the number of victims, and the report did not disclose how many systems were actually infected.

Arctic Wolf assessed that the threat actor was financially motivated. Linguistic and infrastructure indicators suggest that the operators may be Russian-speaking, but there is insufficient evidence to attribute the campaign to a known threat group. The malware’s association with the BoryptGrab family also does not establish the identity of the operators.

How does the malware distribution chain work?

Users typically encounter the fake repositories while searching for free software, trial versions, premium utilities, or gaming tools. Trend Micro previously observed that SEO-optimized repositories could appear immediately below official search results, helping the fake pages appear legitimate.

This campaign adds another scenario to the category of risks discussed by IPSIP Vietnam in its article on software supply chain and source code repository attacks. At the same time, the payload’s in-memory execution and frequent changes demonstrate why antivirus software alone is insufficient for monitoring modern threats.

Who could be affected, and what are the business risks?

The direct targets are Windows users who download software from unofficial GitHub pages. Groups with higher exposure include developers, IT personnel, users of financial or cryptocurrency tools, gamers, and employees who frequently search for free utilities.

In a business environment, an infected workstation could expose:

  • Email accounts and SaaS applications currently signed in through the browser.

  • Session cookies that may allow access without requiring the password to be entered again.

  • Tokens for messaging and collaboration platforms.

  • Credentials stored in Windows Credential Manager.

  • API keys, configuration files, internal documents, or backup files stored in the Desktop and Documents folders.

  • Financial data or cryptocurrency wallet recovery phrases.

What should businesses do right now?

If an employee has downloaded or executed software from a suspicious GitHub repository, the business should treat credentials stored on the device as potentially compromised. Simply deleting the ZIP file or running an antivirus scan is not sufficient to address session cookies, tokens, and passwords that may already have been exfiltrated.

Response checklist for the first 24 hours

  • Isolate the suspected device from the corporate network, but do not delete data before evidence has been collected.

  • Preserve the ZIP file, process information, EDR logs, browser history, DNS records, and network connections for investigation.

  • Change passwords from a clean device and revoke all active login sessions.

  • Revoke OAuth tokens, Discord, Telegram, and Steam tokens, as well as API keys present on the device.

  • Review Windows Credential Manager and replace stored credentials.

  • Check whether other devices downloaded the same file, accessed the same domains, or used the same accounts.

  • Notify legal and data governance teams if personal information or customer data may have been exposed.

Because the campaign succeeds by convincing users to download and execute software, employee cybersecurity awareness training and exercises should include verifying download sources, identifying impersonation pages, and reporting suspicious software before execution.

What does IPSIP Vietnam’s expert perspective Show?

The campaign has not revealed a technical vulnerability in GitHub or the impersonated vendors. The underlying weaknesses are uncontrolled software download processes, excessive trust in search results, and users having permission to execute software on corporate devices.

Vietnamese businesses should treat software downloads as part of asset management and access control. A polished repository, a professional README, or a high Google ranking cannot replace a proper publisher verification process.

What can Businesses implement internally?

Businesses should begin by establishing an approved software catalog, restricting local installation privileges, enabling MFA, applying least privilege, and monitoring endpoints. IT teams should also create processes for revoking tokens and active sessions instead of focusing only on password changes after an incident.

Which IPSIP Vietnam's solutions are suitable for businesses?

24/7 Security Operations Center: After the malware is executed, the main challenge is the lack of visibility into abnormal processes, DLL side-loading, and C2 connections.

IPSIP Vietnam’s 24/7 SOC service can help centralize SIEM and EDR/XDR data and support continuous alert analysis. Detection effectiveness depends on the organization’s telemetry coverage and actual configuration.

IPSIP Vietnam's cybersecurity solutions
IPSIP Vietnam's cybersecurity solutions

Businesses considering an outsourced model can refer to the XDR Outsourcing implementation case study to understand how endpoint technology can be combined with dedicated monitoring resources.

The campaign relies entirely on users trusting and executing fake downloads. IPSIP Vietnam’s Cybersecurity Awareness Training service is suitable for developing exercises involving free software, impersonation pages, phishing, and incident reporting procedures.

References

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
whatsapp-mobile-software-icon-png-image_6315991.png
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page