Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cybercrime Surges in APAC as Digitalization Takes Hold

June 19, 2026

Winners Announced Across 95 Categories

June 19, 2026

ICO Cautions Healthcare Worker After Princess of Wales Incident

June 18, 2026
Facebook X (Twitter) Instagram
Friday, June 19
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Fake GitHub Stars and AI Videos Mask a Crypto Clipper
News

Fake GitHub Stars and AI Videos Mask a Crypto Clipper

Team-CWDBy Team-CWDJune 18, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A cryptocurrency-stealing malware campaign has been spreading by faking its own popularity, dressing up booby-trapped “tools” with bogus GitHub stars, inflated download counts and AI-narrated YouTube tutorials.

New analysis from Check Point Research traced the operation to a Rust-based clipboard hijacker, a “clipper” that swaps copied crypto wallet addresses for the attacker’s own, built for both Windows and macOS.

The lures are “edge” tools that promise easy money, crypto sniper bots and “predictors” that claim to forecast crash-gambling games, aimed at traders and gamblers chasing shortcuts. A WordPress phishing page acts as the hub, funneling victims to the downloads.

Manufacturing Trust

The campaign stands out for the effort it puts into looking legitimate. Check Point said the actor leaned on “Ghost Networks” of fake accounts to manufacture social proof across several platforms, including:

  • Six or more GitHub accounts, with repositories padded out with fake stars and forks

  • SourceForge projects showing 44,485 downloads, most from Android devices despite no Android build

  • A YouTube channel using AI-generated narrators, fake view spikes and coordinated praise

  • VirusTotal entries carrying planted “safe” votes and comments

The VirusTotal trick is among the most novel. Check Point warned that planted “safe” votes, combined with low antivirus detection rates, can fool reputation-based defenses into clearing the files.

The actor even seeded promotional posts on legitimate news sites, some likely paid, others on what may be compromised outlets.

Read more on clipboard hijackers: New SilabRAT Trojan Hijacks Sessions to Steal Crypto

What the Malware Does

The malware itself is straightforward. Once a victim runs the fake tool, a loader launches the Rust clipper, which copies itself for persistence and runs at startup.

From there, it watches the clipboard for anything resembling a crypto wallet address and, when it spots one, silently swaps it for an attacker wallet drawn from an embedded list of more than 15,500 addresses, most of them Bitcoin.

On macOS, the build adds a social-engineering twist: a bundled “unlocker” script that walks users through stripping Apple’s quarantine flag and bypassing Gatekeeper to run the unsigned app.

Both versions dig in for persistence, and the macOS variant runs a 30-second watchdog that rewrites itself and clones the binary to survive manual removal.

Check Point framed the case as a shift in how attackers build trust. Rather than hiding malware, the actor surrounds it with positive signals, so that by the time a victim runs the file, it feels like a normal app.

“These techniques can also be abused by other types of actors distributing and promoting information stealers or other malware families, which can eventually lead to full ransomware compromises in more mature environments,” the firm warned.

“In other words, the same playbook of fake reputation and broad promotion can be reused to deliver more damaging payloads over time.”



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAI Broke Vulnerability Management. That’s Why CISOs Are Moving Budget to BAS.
Next Article ThreatsDay Bulletin: Worm Code Leaked, AI Agent Phished, Claude Code Patch + 28 New Stories
Team-CWD
  • Website

Related Posts

News

Cybercrime Surges in APAC as Digitalization Takes Hold

June 19, 2026
News

Winners Announced Across 95 Categories

June 19, 2026
News

ICO Cautions Healthcare Worker After Princess of Wales Incident

June 18, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

What are brushing scams and how do I stay safe?

December 24, 2025

Can password managers get hacked? Here’s what to know

November 14, 2025

What to consider before asking an AI chatbot for health advice

May 27, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.