Malware Campaign Targets Developers with Fake AI Tools and Cloned Repositories
A large-scale malware campaign has been uncovered, targeting developers and AI users by weaponizing fake AI tools and cloned GitHub repositories.
The attackers impersonate legitimate GitHub repositories associated with popular AI frameworks and developer utilities, increasing the likelihood of successful compromise.
The infection chain is modular, multi-stage architecture built around SmartLoader, a loader increasingly observed in developer-focused malware campaigns.