Close Menu
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
What's Hot

Fake GitHub Stars and AI Videos Mask a Crypto Clipper

June 18, 2026

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

June 18, 2026

Ethereum Foundation loses another key leader as co-executive director Hsiao-Wei Wang resigns

June 18, 2026
Facebook X (Twitter) Instagram
Recession Profit AlertsRecession Profit Alerts
  • Instructions
  • News
    • DeFi
    • Smart Contract
    • Markets
    • Web3
    • Adoption
    • Memecoins
    • Analysis
    • Mining
    • Scams
    • Security
  • Education
    • Learn
    • Wallets & Exchange
  • Documentaries
  • Videos
    • Alessio Rastani
    • Altcoin Buzz
    • Coin Bureau
    • Dapp University
    • DataDash
    • Digital asset News
    • EllioTrades Crypto
    • MMCrypto
    • Lark Davis
    • Ivan on Tech
    • Benjamin Cowen
  • Market
    • Crypto Market Cap
    • Heat Map
    • Converter
    • Metal Prices
    • Stock prices
  • Bonus Books
  • Tools
Recession Profit AlertsRecession Profit Alerts
Home»Security»Fake GitHub Stars and AI Videos Mask a Crypto Clipper
Fake GitHub Stars and AI Videos Mask a Crypto Clipper
Security

Fake GitHub Stars and AI Videos Mask a Crypto Clipper

June 18, 2026No Comments3 Mins Read

A cryptocurrency-stealing malware campaign has been spreading by faking its own popularity, dressing up booby-trapped “tools” with bogus GitHub stars, inflated download counts and AI-narrated YouTube tutorials.

New analysis from Check Point Research traced the operation to a Rust-based clipboard hijacker, a “clipper” that swaps copied crypto wallet addresses for the attacker’s own, built for both Windows and macOS.

The lures are “edge” tools that promise easy money, crypto sniper bots and “predictors” that claim to forecast crash-gambling games, aimed at traders and gamblers chasing shortcuts. A WordPress phishing page acts as the hub, funneling victims to the downloads.

Manufacturing Trust

The campaign stands out for the effort it puts into looking legitimate. Check Point said the actor leaned on “Ghost Networks” of fake accounts to manufacture social proof across several platforms, including:

  • Six or more GitHub accounts, with repositories padded out with fake stars and forks

  • SourceForge projects showing 44,485 downloads, most from Android devices despite no Android build

  • A YouTube channel using AI-generated narrators, fake view spikes and coordinated praise

  • VirusTotal entries carrying planted “safe” votes and comments

The VirusTotal trick is among the most novel. Check Point warned that planted “safe” votes, combined with low antivirus detection rates, can fool reputation-based defenses into clearing the files.

The actor even seeded promotional posts on legitimate news sites, some likely paid, others on what may be compromised outlets.

Read more on clipboard hijackers: New SilabRAT Trojan Hijacks Sessions to Steal Crypto

What the Malware Does

The malware itself is straightforward. Once a victim runs the fake tool, a loader launches the Rust clipper, which copies itself for persistence and runs at startup.

See also  Roaring Kitty hack drains $2.8M from traders

From there, it watches the clipboard for anything resembling a crypto wallet address and, when it spots one, silently swaps it for an attacker wallet drawn from an embedded list of more than 15,500 addresses, most of them Bitcoin.

On macOS, the build adds a social-engineering twist: a bundled “unlocker” script that walks users through stripping Apple’s quarantine flag and bypassing Gatekeeper to run the unsigned app.

Both versions dig in for persistence, and the macOS variant runs a 30-second watchdog that rewrites itself and clones the binary to survive manual removal.

Check Point framed the case as a shift in how attackers build trust. Rather than hiding malware, the actor surrounds it with positive signals, so that by the time a victim runs the file, it feels like a normal app.

“These techniques can also be abused by other types of actors distributing and promoting information stealers or other malware families, which can eventually lead to full ransomware compromises in more mature environments,” the firm warned.

“In other words, the same playbook of fake reputation and broad promotion can be reused to deliver more damaging payloads over time.”

Source link

Clipper Crypto fake GitHub Mask Stars Videos

Related Posts

Aztec Private Rollup Bridge Hit Again as Attackers Drain $2.2 Million

June 18, 2026

France to Phase Out Non-Quantum Encryption as Bitcoin Security Concerns Grow

June 18, 2026

A Single Missing Line of Code Drained $111,000 From the DIP Token

June 18, 2026

Crypto scam losses could reach $17B as approval phishing operations scale, says Chainalysis

June 18, 2026
Top Posts

Chainlink hits Ethereum layer-2 Arbitrum for cross-chain DApp development

September 22, 2023

U.S. To Begin 86-Million-Barrel SPR Dump Next Week Via Exchange Program

March 14, 2026

Stars Arena faces vulnerability that can potentially let users drain funds

October 6, 2023

Type above and press Enter to search. Press Esc to cancel.