
- Kaspersky finds 15 malicious GitHub repositories posing as proof‑of‑concept exploits, some crafted with Gen AI
- Victims receive a ZIP with decoys and a dropper (rasmanesc.exe) that installs WebRAT backdoor/infostealer
- GitHub removed the repos, but infected users must manually eradicate WebRAT and remain cautious of typosquatted packages
Cybercriminals are now targeting security researchers (and possibly other criminals) through malware-laden fake proof-of-concept exploits hosted on popular repositories, experts have warned.