Fake GitHub Repositories Impersonate Brands to Spread BoryptGrab Crypto Wallet Stealer
GitHub is a trusted open-source hosting platform for developers worldwide, but it has also become a breeding ground for malware distribution. As cryptocurrencies and digital finance have grown more widespread, users often turn to the platform to download wallet or cybersecurity tools. By impersonating trusted brands, hackers can bypass traditional defenses and directly steal users’ private keys and sensitive credentials, posing a major threat to digital asset security worldwide. Software supply-chain security on the platform has therefore become a central battleground in cyber defense.
Cybersecurity firm Arctic Wolf disclosed in July 2026 that hackers had created at least 292 fake GitHub repositories impersonating prominent crypto wallets and cybersecurity brands, including MetaMask. Users who downloaded the software were infected with BoryptGrab malware, which stole sensitive credentials from 32 types of crypto wallets and 19 browsers. The campaign used search engine optimization, or SEO, to boost the repositories’ rankings and trick users into downloading them.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →