The prebuild_backdoor is a type of backdoor malware identified in a large-scale campaign targeting public code repositories, particularly GitHub. It is typically embedded in trojanized repositories that masquerade as legitimate Python hacking tools, game cheats, or account utilities. The backdoor enables a range of malicious activities, including data theft, screenshot capture, communication with Telegram for command and control, and the delivery of additional payloads such as AsyncRAT, Remcos RAT, and Lumma Stealer. The campaign, active since at least August 2022, is linked to a Distribution-as-a-Service (DaaS) model and leverages thousands of GitHub accounts, as well as Discord and YouTube for multi-platform dissemination. The primary targets are novice cybercriminals and gamers, with some campaigns specifically targeting communities like Minecraft users. The prebuild_backdoor and related malware have been used to exfiltrate sensitive data, including cryptocurrency wallet information, to attacker-controlled infrastructure. The threat actors behind these campaigns employ techniques such as fake repository stars and frequent updates to increase the visibility and credibility of malicious repositories. All identified malicious repositories have been removed by GitHub, but the threat remains as attackers continue to adapt their methods.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.