Malware Campaign Targets Developers with Fake AI Tools
A large-scale malware campaign targeting developers and AI users has been uncovered, revealing how attackers are using fake AI tools to steal sensitive data.
The campaign, known as 'TroyDen's lure factory', impersonates legitimate GitHub repositories associated with popular AI frameworks and developer utilities.
Victims who download trojanized packages receive a compressed archive containing Lua-based components, including a malicious script disguised as a benign text file.
The malware uses SmartLoader, a loader increasingly observed in developer-focused malware campaigns, to perform reconnaissance and transmit encrypted beacon data to the attacker's C2 server.