A hacker is targeting other hackers, gamers, and researchers, using exploits, bots, and cheats for games contained in source code uploaded to GitHub and including hidden backdoors that give the malicious actor remote access to infected devices.
See also: Hackers exploit serious vBulletin vulnerabilities

This campaign was uncovered by Sophos researchers, who were approached by a client to assess the risk of a remote access trojan called Sakura RAT, which is freely available on GitHub.
Researchers found that the Sakura RAT was essentially non-functional, but it contained a PreBuildEvent in the Visual Studio project that downloaded and installed malware on the devices of those who tried to compile it. Its creator, who goes by the name “ischhfd83,” directly or indirectly linked to 141 other GitHub repositories, 133 of which contained hidden backdoors — revealing a coordinated malware distribution campaign.
The selection of backdoors includes Python scripts with obfuscated payloads, malicious screensaver (.scr) files that use Unicode tricks, JavaScript files with encoded payloads, as well as PreBuild in Visual Studio.
Some repositories appear to have been abandoned since late 2023, however many remain active with regular code submissions (commits), some of which occurred just minutes before Sophos.
See also: Hackers exploit AI to spread ransomware
These submissions are fully automated, with the sole purpose of creating a false image of activity, giving malicious projects the illusion of legitimacy. The number of contributors is consistently limited to three specific users per repository, while different accounts are used for publishing — none of which are associated with more than nine repositories.

These repositories attract traffic through YouTube videos, Discord chats, and cybercrime forum posts. The Sakura RAT itself has received some publicity, attracting the interest of curious “script kiddies,” who have begun searching for it on GitHub. However, when victims download the files, executing or compiling them triggers a multi-step infection stage.
This process involves running VBS scripts on disk, using PowerShell to download an encoded payload from predefined URLs, retrieving a 7zip file from GitHub, and running an Electron application called SearchFilter.exe.
The application loads an embedded file containing a heavily modified main.js and related files, which include code for system profiling, command execution, disabling Windows Defender , and downloading additional payloads.
Additional payloads downloaded by the backdoor include info-stealers and remote access trojans such as Lumma Stealer, AsyncRAT , and Remcos, all with extensive data-stealing.
See also: ConnectWise: State hackers behind the cyberattack?
A key takeaway from the above is how hackers are exploiting the trust that exists in software development communities like GitHub to distribute malware in a sneaky way. What is particularly worrisome is the use of popular tools and programming languages (such as PowerShell, VBS, JavaScript, and Electron), which are usually not suspicious, as well as the incorporation of malicious code into scripts or seemingly innocent open source projects. In doing so, they specifically target communities that are most likely to test or modify such code — such as programmers, gamers, or security researchers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
