Researchers reported a malware campaign that used fake installers and plugins on GitHub and SourceForge to impersonate popular software including ChatGPT, Claude, AutoTune, Kontakt, and Ableton Live, ultimately delivering the Deno-based backdoor DinDoor. The operation was promoted through compromised YouTube channels that posted AI-generated videos linking to malicious repositories; those videos reportedly drew more than 50,000 views before takedowns. Infection chains typically relied on malicious MSI installers or PowerShell-based loaders that installed Scoop and WinGet, then deployed the Deno runtime to fetch and execute staged JavaScript payloads from attacker-controlled infrastructure.
Once installed, DinDoor established persistence, profiled infected systems, and fetched additional malware including a Deno-based RAT capable of remote execution, data theft, screenshot capture, SOCKS5 proxying, and browser credential theft. Researchers said the malware also targeted Telegram, Discord, Lightcord, more than 50 crypto wallet extensions, and at least 10 crypto wallet applications. A standout capability used Microsoft Edge, the Chrome DevTools Protocol, and WebRTC to stream victim screens peer-to-peer while blending malicious traffic with legitimate browser activity. GitHub removed the identified repositories, but researchers warned the operators are likely to keep recreating malicious accounts and projects on trusted platforms.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
Malwarebytes reported that the campaign also used a lighter 'agent-lite' variant alongside DinDoor. The variant leveraged Cloudflare Workers to help anonymize command-and-control communications.
After the malicious repositories were reported, GitHub removed the identified repositories hosting the fake software lures. Researchers warned the operators were likely to continue creating new accounts and repositories on legitimate platforms.
Technical analysis showed DinDoor establishing persistence, profiling infected systems, and deploying additional malware including a Deno-based RAT. Reported capabilities included data theft, remote execution, screenshot capture, browser and crypto wallet theft, SOCKS5 proxying, WebSocket communications, and a peer-to-peer screen-streaming mode abusing Edge/Chrome DevTools Protocol and WebRTC.
The campaign was promoted through compromised YouTube channels posting AI-generated promotional videos that linked to the malicious GitHub and SourceForge repositories. The videos collectively drew more than 50,000 views, increasing victim exposure.
Researchers uncovered a malware distribution campaign using fake installers and plugins impersonating popular software such as ChatGPT, Claude, AutoTune, Kontakt, and Ableton Live on GitHub and SourceForge. The lures delivered the Deno-based backdoor DinDoor through MSI files or PowerShell scripts that installed Scoop, WinGet, and the Deno runtime to execute staged payloads.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcehelpnetsecurity.com
Open sourcemalware.news
Open sourcemalwarebytes.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.