{"id":52768,"date":"2023-07-14T14:17:16","date_gmt":"2023-07-14T14:17:16","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/34800\/Fake-PoC-On-GitHub-Lures-Researchers-To-Download-Malware.html"},"modified":"2023-07-14T14:17:16","modified_gmt":"2023-07-14T14:17:16","slug":"fake-poc-on-github-lures-researchers-to-download-malware","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/","title":{"rendered":"Fake PoC On GitHub Lures Researchers To Download Malware"},"content":{"rendered":"<p>Threat actors have crafted a novel ploy designed to bait cybersecurity researchers into a trap by posting a fake proof-of-concept (PoC) to GitHub that is actually a backdoor.&nbsp;<\/p>\n<p>R<a rel=\"noreferrer noopener\" href=\"https:\/\/www.uptycs.com\/blog\/new-poc-exploit-backdoor-malware\" target=\"_blank\">esearchers at Uptycs<\/a> outlined the scam on Wednesday in a blog breaking down the discovery of the bogus PoC. They said the PoC contained a malicious downloader, or dropper, hidden inside the code. Once downloaded, the dropper delivers the malware payload that eventually executes a Linux Bash script that is disguised as a kernel-level process. A Bash scrip is a simple text files that automates commands.<\/p>\n<p>\u201cAs their primary users, security researchers rely on PoCs to understand potential vulnerabilities by way of innocuous test,\u201d co-authors of the blog Nischay Hegde and Siddartha Malladi wrote. They said the malware \u201cleverages the make command to create a kworker file and adds its file path to the bashrc file, thus enabling the malware to continually operated within a victim\u2019s system\u201d in order to gain persistence.<\/p>\n<p>The malicious PoC operates as a downloader, with the malware payload capable of data theft via exfiltration. Targeted is the system&#8217;s hostname and username and the malware&#8217;s ability to scrape a computer&#8217;s home directory, Hegde and Malladi said. An attacker can also gain full access to a target system by adding their SSH Key to the targeted system&#8217;s authorized_keys file.<\/p>\n<p>&#8220;SSH (Secure Shell) keys are an access credential that is used in the SSH protocol and they are foundational to modern Infrastructure-as-a-Service platforms such as AWS, Google Cloud, and Azure,&#8221; according to a <a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">breakdown<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">o<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">f<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">t<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">h<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">e<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">t<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">e<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\">r<\/a><a href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\" rel=\"noreferrer noopener\">m<\/a><a rel=\"noreferrer noopener\" href=\"https:\/\/jumpcloud.com\/blog\/what-are-ssh-keys\" target=\"_blank\"> by vendor JumpCloud<\/a>. &nbsp;&nbsp;<\/p>\n<p>The fake PoC exploits the critical vulnerability (CVE-2023-35829). The malware-laced PoC was shared widely before the malicious contents were discovered and removed from GitHub, researchers said.<\/p>\n<p>Uptycs researchers said they encountered unusual activity while testing PoCs of various CVEs. They said they noticed suspicious activity such as unexpected network connects, unusual data transfers and unauthorized system access attempts.<\/p>\n<figure><img alt srcset=\"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=750&amp;q=75 1x, https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75 2x\" src=\"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75\" width=\"697\" height=\"418\" decoding=\"async\" data-nimg=\"1\" class=\"MediaItem_img__WJ8V4\" loading=\"lazy\"><figcaption>A GitHub profile page of a fake POC. (via Uptycs)<\/figcaption><\/figure>\n<p>It\u2019s not the first time GitHub has been used for nefarious purposes. In June, Vulncheck researchers reported finding <a rel=\"noreferrer noopener\" href=\"https:\/\/www.scmagazine.com\/news\/devops\/someone-is-posing-as-a-fake-security-company-to-create-malicious-github-repositories\" target=\"_blank\">malicious GitHub repositories <\/a>under the guise of a fake company.<\/p>\n<p>Security researchers contacted by SC Media said the method uncovered by Uptycs was interesting, but Mike Parkin, senior technical engineer at Vulcan Cyber, said the target audience was uniquely positioned to quickly discover and eliminate the attack.&nbsp;<\/p>\n<p>\u201cIf they are experimenting with a PoC someone else developed, they are likely to do so in a virtual machine, which can be quickly reset if something goes wrong,\u201d said Parkin.&nbsp;<\/p>\n<p>\u201cI would be shocked, and a bit disappointed, if any experienced malware researchers were caught by this,\u201d he said.<\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/34800\/Fake-PoC-On-GitHub-Lures-Researchers-To-Download-Malware.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[4764],"class_list":["post-52768","post","type-post","status-publish","format-standard","hentry","category-cybersecurity-blogs","tag-headlinehackermalwaremicrosoftbackdoor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Fake PoC On GitHub Lures Researchers To Download Malware 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Fake PoC On GitHub Lures Researchers To Download Malware 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-14T14:17:16+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Fake PoC On GitHub Lures Researchers To Download Malware\",\"datePublished\":\"2023-07-14T14:17:16+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/\"},\"wordCount\":474,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scmagazine.com\\\/_next\\\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75\",\"keywords\":[\"headline,hacker,malware,microsoft,backdoor\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/\",\"name\":\"Fake PoC On GitHub Lures Researchers To Download Malware 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.scmagazine.com\\\/_next\\\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75\",\"datePublished\":\"2023-07-14T14:17:16+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.scmagazine.com\\\/_next\\\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75\",\"contentUrl\":\"https:\\\/\\\/www.scmagazine.com\\\/_next\\\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/fake-poc-on-github-lures-researchers-to-download-malware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,malware,microsoft,backdoor\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackermalwaremicrosoftbackdoor\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Fake PoC On GitHub Lures Researchers To Download Malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Fake PoC On GitHub Lures Researchers To Download Malware 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/","og_locale":"en_US","og_type":"article","og_title":"Fake PoC On GitHub Lures Researchers To Download Malware 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2023-07-14T14:17:16+00:00","og_image":[{"url":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Fake PoC On GitHub Lures Researchers To Download Malware","datePublished":"2023-07-14T14:17:16+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/"},"wordCount":474,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75","keywords":["headline,hacker,malware,microsoft,backdoor"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/","url":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/","name":"Fake PoC On GitHub Lures Researchers To Download Malware 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75","datePublished":"2023-07-14T14:17:16+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/#primaryimage","url":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75","contentUrl":"https:\/\/www.scmagazine.com\/_next\/image?url=https%3A%2F%2Ffiles.scmagazine.com%2Fwp-content%2Fuploads%2F2023%2F07%2Fuptycs_fake_profile.webp&amp;w=1920&amp;q=75"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/fake-poc-on-github-lures-researchers-to-download-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,malware,microsoft,backdoor","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackermalwaremicrosoftbackdoor\/"},{"@type":"ListItem","position":3,"name":"Fake PoC On GitHub Lures Researchers To Download Malware"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52768","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=52768"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/52768\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=52768"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=52768"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=52768"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}