A new and highly sophisticated software supply chain attack is underway, primarily targeting IT administrators , cybersecurity professionals , and Open Source Intelligence (OSINT) analysts . The campaign leverages the trustworthiness of GitHub , one of the world’s leading software development ecosystems, to distribute the PyStoreRAT malware through seemingly innocent repositories.

Unlike classic, mass attacks that target unsuspecting users, there is strategic planning here. The perpetrators choose technically competent targets, knowing that they often download tools from open-source communities and trust code that appears active and popular.
See also: German agencies warn about phishing via Signal
Reactivating old accounts for greater credibility
The first step of the attack is particularly insidious: the attackers are reviving GitHub accounts that have been inactive for years. This choice is not accidental. An old account, with a history of presence on the platform, looks more trustworthy than a brand new one, thus reducing the chances of arousing suspicion.
Once these accounts "come back to life," they begin publishing well-designed software repositories, which in many cases have been produced or enriched with the help of Artificial Intelligence.
These projects are disguised as useful tools, such as:
- bots for cryptocurrency trading
- GPT wrappers and AI utilities
- penetration testing tools or OSINT utilities
AI allows perpetrators to quickly fill repositories with code that looks legitimate, creating the illusion that these are active and maintained projects.
From “trending” repositories… to the trap
Morphisec analysts spotted the campaign when they noticed that several of these suspicious repositories had managed to appear on GitHub's trending lists.
See also: Odyssey Stealer: New malware campaign targets Mac computers
This is especially important, as visibility on such lists brings malware right in front of the target audience: developers, sysadmins, and researchers looking for new tools.

Once the repositories gain downloads and a positive reputation, attackers move on to the next stage: introducing “innocent” maintenance updates.
Within these commits lies the real threat: a previously unknown backdoor, which researchers have named PyStoreRAT.
PyStoreRAT: Malware for persistence and data theft
PyStoreRAT is not just a trojan. It is a tool designed to remain on infected systems and gradually collect information.
Once installed, it functions as a loader , capable of:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- profiling the target system
- installation of additional payloads
- data collection from applications and browsers
One of the key payloads that has already been observed is the Rhadamanthys stealer, a notorious tool for stealing credentials and financial information.
Even more worryingly, PyStoreRAT can also spread via removable drives (USB), significantly increasing its potential spread within corporate networks.
See also: 'DKnife': New malicious framework for AitM attacks
Detection avoidance and resilient C2 infrastructure
One of the most advanced features of the threat is its ability to adapt to the defense environment.
PyStoreRAT performs checks to detect specific antivirus and EDR solutions, such as:
- CrowdStrike Falcon
- ReasonLabs
If it detects such defenses, it changes the execution method and uses alternative launch paths to avoid triggering alarms.

Meanwhile, the campaign's Command-and-Control (C2) infrastructure is designed with resilience in mind , using a hot-swapped node system that allows for rapid migration to new servers when some become blocked. This makes it extremely difficult for defense teams to disrupt the operation
Also of interest is the presence of Russian strings within the code, an element that may indicate geographical origin or targeting, but does not constitute proof.
What organizations and security professionals should do
Experts warn that traditional defenses, based solely on signatures, are no longer sufficient against such evolving threats.
Behavior-based detection strategies are recommended , as well as stricter vetting of open-source tools before their installation.
This new attack is yet another reminder that GitHub, as useful as it is, can become an ideal vehicle for supply chain attacks, especially when attackers exploit the trust and momentum of the community.
