Threat actors abused trusted developer distribution channels to deliver malware by impersonating popular tools. Research described a campaign that forked the official GitHub Desktop repository, altered README download links to point to a malicious Windows installer, and then drove victims to the poisoned links via sponsored ads targeting searches for “GitHub Desktop.” The technique leveraged GitHub behavior where commits from forks can remain visible under the upstream project’s namespace even after the attacker’s fork/account is deleted (a form of repo squatting), complicating takedown efforts; the observed payload (GitHubDesktopSetup-x64.exe, ~127.68 MB) functioned as a multi-stage loader, and similar installer-themed lures (e.g., Chrome, Notion, 1Password, Bitwarden) were reported in related activity.
Separately, a fake “ClawdBot Agent” VS Code extension was identified as a functional trojan that executed automatically on VS Code startup ("activationEvents": ["onStartupFinished"]) and dropped malware on Windows systems; the legitimate Clawdbot project reportedly had no official VS Code extension, enabling name-squatting/impersonation. The extension fetched configuration from http://clawdbot.getintwopc[.]site/config.json and installed a ScreenConnect RAT, and it was reported to Microsoft and removed. Two additional posts about Clawdbot focused on general SOC monitoring and broader “AI agent” security considerations rather than the specific malware/impersonation incidents.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
After being notified, Microsoft removed the malicious "ClawdBot Agent" extension from the Visual Studio Code marketplace.
Analysis showed the extension fetched remote configuration, downloaded a weaponized ConnectWise ScreenConnect client configured to connect to attacker-controlled infrastructure, and also used a Rust-based malicious DWrite.dll sideloading path with multiple fallback delivery mechanisms.
On January 27, 2026, a newly published VS Code extension named "ClawdBot Agent" was identified as a trojan posing as an AI coding assistant that automatically dropped malware on Windows when VS Code started.
GMO Cybersecurity reported that the fake GitHub Desktop Windows installer used a multi-stage loader disguised as a C++ app but actually built as a single-file .NET AppHost, with GPU-dependent anti-sandbox checks and code-misdirection to hinder analysis.
From September to October 2025, attackers targeted developers, mainly in Europe and the EEA, by promoting sponsored ads for "GitHub Desktop" and using a fork of the official GitHub Desktop repository with altered download links to deliver a trojanized installer.
By May 2025, attackers were distributing trojanized installers masquerading as Chrome, Notion, 1Password, and Bitwarden, indicating the start of a broader malware campaign using fake software downloads.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.