Security researchers reported a supply-chain campaign targeting developers by impersonating legitimate AI-related tooling and luring victims into installing malware. A malicious PyPI package, grokwrapper, posed as an unofficial API wrapper for xAI’s Grok and used a common “benign-first, malicious-later” publishing pattern: an initial clean release was followed by a weaponized update intended to evade registry and scanner scrutiny. Once installed, the package was described as downloading and executing a second-stage payload, establishing persistence via Windows Registry changes, and maintaining access using DLL sideloading with a legitimate Microsoft binary (wkspbroker.exe), with targeting described as focused on developers outside CIS countries and consistent with tradecraft associated with DPRK-linked activity (including references to Operation DreamJob expansion beyond prior sectors).
Separately, a maintainer documented abuse of a forked GitHub repository to distribute malware by converting the project’s README into a fake Windows “installer” landing page and embedding a ZIP payload directly in the source tree (rather than using GitHub Releases or a package manager). The attacker then rewired “Download” links to the embedded archive, mirrored the content via GitHub Pages, and reused the original project’s topics/metadata to drive SEO hijacking, increasing the chance that searches for enterprise AI integration terms would land on the malicious fork while the original author’s name appeared as a contributor due to inherited commit history. Together, the incidents highlight active abuse of trusted developer ecosystems (PyPI and GitHub) to deliver Windows malware through social engineering and dependency/asset trust assumptions.

Trace attribution and downstream blast radius.
2 events from the most recent confirmed update back to the earliest known activity.
A post on Reducibl reported that someone forked the author's AI governance repository and used it to distribute malware. The provided reference does not include further dated milestones beyond the publication of the report.
Safety published a blog post titled "grokwrapper". No additional incident details are available in the provided reference content.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.