Fake GitHub pages impersonating Arctic Wolf and other software vendors are spreading BoryptGrab stealer malware

Attackers created fake GitHub pages that impersonate Arctic Wolf and many other software brands to trick people into downloading malware. Arctic Wolf says one bogus repository used an 'Official Page' link to deliver a ZIP file containing a trojanized installer, 'Arctic-Wolf-3.9.7.exe,' which side-loaded a fake libcurl.dll to decrypt and launch BoryptGrab Stealer, an information-stealing malware family. The company says it found nearly 300 similar repositories using search-engine bait and branding from vendors including Malwarebytes, Bitdefender, and 360 Total Security.
Why it matters: This is a broad social-engineering and malware campaign that can hit employees and consumers who trust GitHub pages and software downloads that look official. Organizations should warn users, block known indicators, and tell staff to download tools only from verified vendor sites or trusted repositories.

Sources

Nearly 300 GitHub repos pose as legit software to push malware
Bill Toulas 2026.07.14 98% relevant
This is the same underlying campaign: hundreds of fake GitHub repositories and GitHub Pages impersonating software brands, including Arctic Wolf, to deliver BoryptGrab infostealer malware. The article adds the count of 292 fake repos, details on the templated landing pages, the trojanized libcurl.dll plus signed WinGUP sideload chain, and the stealer’s Chrome App-Bound Encryption bypass behavior.
Security Bulletin: GitHub Impersonation Deploys Information Stealer
Arctic Wolf Labs 2026.07.02 100% relevant
This article appears to be the first concrete report in the set establishing this specific fake-GitHub vendor-impersonation campaign and naming BoryptGrab Stealer as the payload.
← Back to all stories