CYBERSECURITYTRACKER
TRACKING7,004 stories in this site build1,474 vulnerability news stories in this site build
Permanent story citation

AI developers targeted via trojanized GitHub repositories

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3815

As cited

Copy frozen at (site build).

threat intel

AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning popular GitHub repositories for AI tools and spreading an infostealer through fake repositories using a malware-as-a-service model. Netskope Threat Labs tracked the campaign after initial distribution through ClickFix social engineering, and observed the threat actors shift delivery tactics to impersonated GitHub repositories hosting developer resources.

Why it matters: AI developers and teams relying on GitHub for dependencies face credential theft and system compromise when downloading from trojanized repositories; practitioners should verify repository authenticity and monitor for suspicious clones of commonly used projects.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

AI developers targeted via trojanized GitHub repositories

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning legitimate GitHub repositories for artificial intelligence (AI) tools and developer resources to distribute an infostealer targeting developers. The group previously used ClickFix social engineering to spread a Windows-based malware-as-a-service (MaaS) infostealer reported in April 2026, then shifted tactics to trojanized repository mirrors for broader reach.

Why it matters: AI developers and engineers who clone or fork GitHub repositories face credential theft and system compromise; practitioners should advise teams to verify repository authenticity and monitor for suspicious clones of popular projects.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

threat intel

AI developers targeted via trojanized GitHub repositories

Cybercriminals are cloning legitimate GitHub repositories for artificial intelligence (AI) tools and developer resources to distribute an infostealer targeting developers. The group previously used ClickFix social engineering to spread a Windows-based malware-as-a-service (MaaS) infostealer reported in April 2026, then shifted tactics to trojanized repository mirrors for broader reach.

Why it matters: AI developers and engineers who clone or fork GitHub repositories face credential theft and system compromise; practitioners should advise teams to verify repository authenticity and monitor for suspicious clones of popular projects.

VendorsMicrosoftGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary