Dangerous WebRAT malware now being spread by GitHub repositories

  • Kaspersky finds 15 malicious GitHub repositories posing as proof‑of‑concept exploits, some crafted with Gen AI
  • Victims receive a ZIP with decoys and a dropper (rasmanesc.exe) that installs WebRAT backdoor/infostealer
  • GitHub removed the repos, but infected users must manually eradicate WebRAT and remain cautious of typosquatted packages

Cybercriminals are now targeting security researchers (and possibly other criminals) through malware-laden fake proof-of-concept exploits hosted on popular repositories, experts have warned.

Cybersecurity researchers Kaspersky said they found 15 malicious repositories hosted on GitHub. These repositories, apparently crafted with the help of Generative Artificial Intelligence (Gen AI), claimed to provide an exploit for multiple vulnerabilities discovered and reported in the media.

Among them is a heap-based buffer overflow bug in Windows MSHTML/Internet Explorer, a critical authentication bypass in OwnID Passwordless Login plugin for WordPress, and an elevation-of-privilege flaw in Windows’ Remote Access Connection Manager.

Backdoor and infostealer

Victims who download packages find a password-protected ZIP archive with an empty file, a fake DLL file that serves as a decoy, a batch file, and a malicious dropper named rasmanesc.exe.

This dropper elevates its privileges, disables Windows Defender, and then downloads the WebRAT malware.

WebRAT is primarily a backdoor, but it also works as an infostealer. Security researchers said it can steal login credentials for Steam, Discord, and Telegram accounts, as well as information from any cryptocurrency wallets and browser add-ons that the victim might have installed. It can also use the webcam to spy on its victims, and grab screenshots.

The campaign seems to have started in September 2025, so it’s been active for a few months now. However, GitHub has now removed all of the malicious repositories.

Still, victims who already downloaded the packages will not be safe until they remove any traces of WebRAT from their systems. Furthermore, they should be wary about downloading additional packages, since it is possible that there are more out there that have not yet been discovered.

Due to its size and popularity in the software dev/cybersecurity community, GitHub is a major target for cybercriminals, who often try to typosquat their way into people’s devices.

Via BleepingComputer

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!

And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.

Read more @ TechRadar

Latest posts

We translated the Palantir manifesto for actual human beings

Palantir CEO Alex Karp is a man in charge of one of the most important and frightening companies in the world. Karp's new book,...

SpaceX cuts a deal to maybe buy Cursor for $60 billion

With an IPO looming for Elon Musk's SpaceX / xAI / X combo platter of companies, SpaceX has announced an odd arrangement to either...

YouTube is muting push notifications from channels you don’t watch

YouTube notifications can get messy fast, particularly if you’re subscribed to a lot of different channels. To address that, today the company will begin...

Cash App now supports accounts for kids 6-12

Cash App, the banking and payments app run by Block, has added support for parent-managed kids accounts. The new accounts include key benefits from...

Mozilla says it patched 271 Firefox vulnerabilities thanks to Anthropic’s Claude Mythos

Anthropic's buzzy announcement about using AI to improve cybersecurity earlier this month was met with plenty of skepticism. However, Mozilla shared some details that...

SpaceX and Cursor strike partnership that might end in a $60 billion acquisition

SpaceX and AI company Cursor have struck a new partnership that could see the owner of X buy the AI company for $60 billion...

Google Wallet adds Live Update for flight tracking

As previously teased, Google Wallet for Android now offers Live Updates for tracking your current flight. Read more @ 9to5google

The AirPods are Tim Cook’s most underrated achievement

The AirPods changed the direction of true wireless earbuds and became Apple’s most important accessory. | Photography by Amelia Holowaty Krales / The Verge Apple...

Framework is building a better couch keyboard because everyone hates the Logitech one

If you have a wireless keyboard with a touchpad that lets you control your PC from across the room, chances are it's a Logitech...

Framework’s first eGPUs turn its laptop into a desktop PC

Remember when Framework made the first laptop where you can easily upgrade its entire internal video card in three minutes flat? The company's getting...