Attackers are using cloned GitHub repositories that impersonate AI and developer tools to infect users with a multi-stage SmartLoader chain that ends in infostealer deployment, according to reporting from Netskope Threat Labs and related indicator data. The campaign targets AI users and developers, with observed victim concentration in North America, Asia, and Southern Europe, particularly across financial services, banking, and technology organizations. Netskope said the final payload includes a previously reported NodeJS-based Malware-as-a-Service infostealer, turning developer interest in AI tooling into a potential enterprise initial-access vector.
The infection chain relies on Windows-hosted Lua components packaged in ZIP archives and staged through files including lua51.dll, a renamed interpreter such as compiler.exe, Application.bat, obfuscated Lua payloads such as dist.lua, and follow-on executables including 7d7752.exe. Both SmartLoader stages reportedly retrieve command-and-control data dynamically from a Polygon blockchain smart contract using EtherHiding, with supporting indicators showing Polygon RPC endpoints, eth_call activity, an Ethereum-style wallet address, and GitHub-hosted files tied to accounts including yawalinte and JuliusMAAR. Netskope also found signs of Prometheus obfuscation in the first-stage Lua payload and MoonSec V3-style obfuscation in the second stage, indicating a resilient loader design that lets operators rotate C2 infrastructure without changing malware code.

Pull IOCs and campaign context straight into your stack.
3 events from the most recent confirmed update back to the earliest known activity.
Netskope identified the GitHub account JuliusMAAR as another GitHub account serving identical payloads in the same campaign. The account was created on July 26, 2026.
Netskope identified the GitHub account yawalinte as serving payloads used in the campaign. The account was created on July 21, 2026.
Netskope Threat Labs reported an ongoing campaign targeting AI users and developers through cloned GitHub repositories impersonating legitimate AI and developer resources. The campaign shifted delivery from earlier ClickFix-based lures to malicious payloads hosted in impersonated repositories and used a multi-stage SmartLoader chain ending in infostealer deployment.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecryptika.com
Open sourcenetskope.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.