Threat actors abused GitHub to distribute malware by cloning legitimate repositories, impersonating trusted open-source projects, and poisoning search results to steer victims to trojanized downloads. One campaign spoofed the AIMMY game-cheat project through a cloned repository and the lookalike site aimmy.app, while also exploiting GitHub's issue-draft upload behavior to host malicious files on the original benign repository via direct links that appeared trustworthy. The delivered packages included files such as Aimmy.bat, AimmyLauncher.exe, lua51.dll, and supporting data, with the malware implemented through obfuscated LuaJIT code.
Follow-on analysis tied similar GitHub repo poisoning activity to SmartLoader, which used trojanized lua51.dll components and heavily obfuscated Lua payloads to deploy StealC infostealer. The malware performed anti-debugging and anti-tamper checks, captured screenshots, verified connectivity and geolocation, and fetched additional payloads from attacker-controlled GitHub repositories. Researchers found it also used the EtherHiding technique, querying the Polygon PoS blockchain for dynamically updated command-and-control data, before exfiltrating browser credentials, cookies, cryptocurrency wallet information, and email data to attacker infrastructure including 213.176.72[.]200.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Analysis of the SmartLoader campaign found the Lua-based malware used the EtherHiding technique, querying Polygon Proof-of-Stake RPC infrastructure and a smart contract to retrieve dynamically updated command-and-control information. The malware also performed anti-debugging, persistence, geolocation checks, screenshot capture, and downloaded additional payloads including StealC from attacker-controlled GitHub repositories.
OALABS published research describing the AIMMY impersonation campaign and the delivered package containing files such as Aimmy.bat, AimmyLauncher.exe, lua51.dll, README.txt, and a data directory. The researchers also described instrumenting LuaJIT and modifying functions such as lj_str_free and os_execute to analyze the obfuscated Lua payload.
Threat actors were observed cloning or forking legitimate public GitHub repositories for tools such as game cheats, AI utilities, validators, and coding extensions, then seeding them with a malicious SmartLoader package that ultimately deploys StealC Infostealer. In the observed case, they duplicated the Security-Camera-w-AI repository and added a malicious payload archive.
The AIMMY-themed campaign used GitHub's issue-draft upload behavior to place a malicious Aimmy.zip payload under the original benign Babyhamsta/Aimmy repository, then linked directly to that file so the download appeared trustworthy. The content states uploaded files remain accessible even if the issue is never submitted, leaving no visible trace beyond the direct link.
Malware operators cloned the legitimate Babyhamsta/Aimmy GitHub repository and created the lookalike website aimmy.app to impersonate the AIMMY project and trick users searching for the cheat tool into downloading malware. The campaign also relied on likely SEO poisoning to rank the malicious site above the legitimate aimmy.dev site.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
jmp-esp.org
Open sourceresearch.openanalysis.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.