A new cyber threat has been discovered by researchers at ReversingLabs, after they identified more than 67 malicious GitHub repositories that falsely present themselves as Python-based hacking tools, but in fact distribute trojanized payloads.

The campaign, dubbed “Banana Squad” (after the hackers), appears to be a follow-up to a previous attack recorded in 2023, when fake Python packages on the popular Python Package Index (PyPI) repository were downloaded more than 75,000 times, including malware designed to steal data from Windows systems.
See also: Hacker targets other hackers and gamers with hidden GitHub code
The latest findings are based on research by SANS's Internet Storm Center from November 2024, which described a tool called “steam-account-checker .” Although seemingly innocent, the tool contained hidden features that downloaded additional malicious Python payloads , targeting the Exodus cryptocurrency wallet app among others , and collecting sensitive information.
By analyzing the infrastructure behind GitHub repositories, researchers uncovered dozens of clones of legitimate repositories that actually contained malicious code, misleading users looking for apps like “Discord account cleaner”, “Fortnite External Cheat”, “TikTok username checker” or “PayPal bulk account checker”.
See also: GitHub's new Sakura RAT evades AV & EDR protections
All of the identified repositories have already been removed from GitHub. However, ReversingLabs warns that the use of open source platforms like GitHub as a means of distributing malicious code is increasing at an alarming rate.
GitHub targeted by hackers
Meanwhile, another research by Trend Micro recently revealed that the “Water Curse” was using 76 malicious GitHub repositories to distribute multi-stage malware, which aimed to steal credentials, browsing data, and login tokens, while also securing permanent remote access to victims’ devices.
See also: GitHub's new Sakura RAT evades AV & EDR protections

Ways of Protection
1. Verify GitHub repositories
- Always check the number of stars, forks, issues, and history of the repo.
- Prefer repositories from verified organizations or well-known accounts.
2. Critical thinking before using “cheat tools”
- Many repositories target users looking for “cracks,” “cheats,” or “account checkers.” They are high-risk and usually hide traps.
3. Code analysis before execution
- Specifically for Python: if you don't know what each line of code does, don't run it on your system.
4. Using sandboxing
- Run suspicious tools (found in GitHub repositories) inside virtual machines (VMs) or containers, not on the main operating system.
5. Antivirus/antimalware check
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Before running any script, run it through good antivirus solutions or upload it to VirusTotal for analysis.
Source: thehackernews.com
