Was this helpful?
Thumbs UP Thumbs Down

GitHub repositories are now spreading dangerous WebRAT malware

Github logo displayed on phone screen
Github logo displayed on a phone screen

A new threat hides in plain sight

That handy game cheat or software patch you downloaded could be a wolf in sheep’s clothing. Cybersecurity researchers have uncovered a disturbing new trend. Malicious actors are now using trusted platforms like GitHub to spread dangerous malware.

This malware, called WebRAT, is being distributed via fake GitHub repositories that pose as useful proof-of-concept tools.

Group of students

Hackers shift their targeting strategy

The criminals behind Webrat have changed their bait. Originally, they focused on people looking for game hacks or pirated software. Now, they are also targeting students and newcomers in the cybersecurity field.

They prey on the curiosity of those eager to learn. By posing as a source for real exploit code, they trap inexperienced users.

A hacker using his laptop

Fake exploits for real vulnerabilities

The hackers create fake solutions for genuine, high-profile security flaws. The fake repositories claim to provide exploits for real vulnerabilities, including CVE-2025-59230, to lend legitimacy to the pages.

This use of actual issues makes the trap very convincing. People researching these specific flaws become the primary victims.

Doctor hold artificial intelligence concept icon

AI-generated trust

The fake repository pages are remarkably detailed and well-structured. They include sections like overviews, installation guides, and mitigation steps. This polished presentation is designed to build immediate trust with the viewer.

Researchers say many of the repositories were created or polished using generative artificial intelligence to rapidly produce convincing technical write-ups.

Login verification passcode on a phone

The password trick

Clicking the download link provides a password-protected ZIP file. The repositories deliver a password-protected ZIP file in which an empty file is included, and its filename contains the password needed to open the archive.

This extra step makes the download feel more exclusive and legitimate. It also helps the malicious file evade some automated security checks.

Archive concept

Decoy files distract you

Inside, researchers found an empty file whose filename contains the archive password and a corrupted DLL file that acts as a decoy to make the package look authentic.

These items are pure misdirection. They make the package look more complex and authentic, drawing attention away from the real threat.

Windows defender logo displayed on phone

The malicious dropper

The archive contains a dropper executable, typically named rasmanesc.exe, and a batch script that runs it; executing these files triggers privilege escalation, disables Windows Defender, and downloads the full WebRAT payload.

It first seeks administrator-level control over your system. Its next move is to disable security tools like Windows Defender.

Businessman pressing download button

Downloading the full attack

With defenses down, the dropper connects to a hacker-controlled server. It fetches and installs the complete Webrat malware onto your machine. This entire process happens quietly in the background.

The attackers now have a persistent backdoor into your computer. They can execute commands and steal data at will.

Discord logo displayed on a phone screen

What the malware steals

Webrat is a powerful information-stealing tool. It hunts for login credentials for platforms like Steam, Discord, and Telegram. The malware also scours your system for valuable cryptocurrency wallet data.

Its capabilities extend beyond simple theft. It can log your keystrokes, capture screenshots, and even activate your webcam.

Github logo displayed on phone screen

Why this trap works

Hackers exploit the inherent trust people place in platforms like GitHub. They know that students and professionals visit the site for legitimate code samples. By using AI to create convincing fake pages, they cast a wide net.

This campaign cleverly preys on professional curiosity and the desire to learn. It proves that being tech-oriented does not make you immune to deception.

Safety written on road

How to stay protected

Always approach online downloads with healthy skepticism, even from reputable sites. If you need to examine unknown code, always use a secure, isolated environment. A virtual machine acts as a digital containment lab, keeping your main system safe.

Never run suspicious executables directly on your primary computer. This simple habit is your strongest defense.

Want to see how AI is shaping safer coding practices? Check out what’s new with GitHub Copilot.

Verification concept

Guard your digital life

The internet is an incredible resource for knowledge and tools. This incident reminds us that vigilance is our constant responsibility. Always verify the sources of your downloads and look for community feedback.

Your personal data and privacy are worth protecting. A moment of caution can prevent a devastating loss of your sensitive information.

Stay sharp by learning from the best. See why this GitHub leader values fresh perspectives.

Have you ever double-checked a download after hearing about scams like this? Share your own safety tip in the comments.

This slideshow was made with AI assistance and human editing.

Don’t forget to follow us for more exclusive content on MSN.

Read More From This Brand:

This content is exclusive for our subscribers.

Get instant FREE access to ALL of our articles.

Was this helpful?
Thumbs UP Thumbs Down
Prev Next
Share this post

Lucky you! This thread is empty,
which means you've got dibs on the first comment.
Go for it!

Send feedback to ComputerUser



    We appreciate you taking the time to share your feedback about this page with us.

    Whether it's praise for something good, or ideas to improve something that isn't quite right, we're excited to hear from you.