Tech Wavo
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock
Tech Wavo
No Result
View All Result

Fraudulent GitHub Pages impersonate trusted companies to trick Mac users into installing malware, leaving financial and personal data at risk

Tech Wavo by Tech Wavo
September 24, 2025
in Computers
0




  • Atomic Stealer malware installs silently via fake GitHub Pages targeting Mac users
  • Attackers create multiple GitHub accounts to bypass platform takedowns repeatedly
  • Users copying commands from unverified websites risk serious system compromise

Cybersecurity researchers are warning Apple Mac users about a campaign using fraudulent GitHub repositories to spread malware and infostealers.

Research from LastPass Threat Intelligence, Mitigation, and Escalation (TIME) analysts found attackers are impersonating well-known companies to convince people to download fake Mac software.

Two fraudulent GitHub pages pretending to offer LastPass for Mac were first spotted on September 16 2025 under the username “modhopmduck476.”


You may like

How the attack chain works

While these particular pages have been taken down, the incident suggests a broader pattern that continues to evolve.

The fake GitHub pages included links labeled “Install LastPass on MacBook,” which redirected to hxxps://ahoastock825[.]github[.]io/.github/lastpass.

From there, users were sent to macprograms-pro[.]com/mac-git-2-download.html and told to paste a command into their Mac’s terminal.

That command used a CURL request to fetch a base64-encoded URL that decoded to bonoud[.]com/get3/install.sh.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

The script then delivered an “Update” payload that installed Atomic Stealer (AMOS malware) into the Temp directory.

Atomic Stealer, which has been active since April 2023, is a known infostealer used by financially motivated cybercrime groups.

Investigators have linked this campaign to many other fake repositories impersonating companies ranging from financial institutions to productivity apps.


You may like

The list of targeted names includes 1Password, Robinhood, Citibank, Docker, Shopify, Basecamp, and numerous others.

Attackers appear to create multiple GitHub usernames to bypass takedowns, using Search Engine Optimization to push their malicious links higher on search results in Google and Bing.

This technique increases the chances that Mac users searching for legitimate downloads will encounter the fraudulent pages first.

LastPass states it is “actively monitoring this campaign” while working on takedowns and sharing indicators of compromise to help others detect threats.

The attackers’ use of GitHub Pages reveals both the convenience and the risks of community platforms.

Fraudulent repositories can be set up quickly, and while GitHub can remove them, attackers often return under new aliases.

This cycle raises questions about how effectively such platforms can protect users.

How to stay safe

  • Only download software from verified sources to avoid malware and ransomware risks.
  • Avoid copying commands from unfamiliar websites to prevent unauthorized code execution.
  • Keep macOS and all installed software up to date to reduce vulnerabilities.
  • Use the best antivirus or security software that includes ransomware protection to block threats.
  • Enable regular system backups to recover files if ransomware or malware strikes.
  • Stay skeptical of unexpected links, emails, and pop-ups to minimize exposure.
  • Monitor official advisories from trusted vendors for timely security updates and guidance.
  • Configure strong, unique passwords and enable two-factor authentication for important accounts.

You might also like

Previous Post

Qualcomm Debuts Snapdragon X2 Elite and X2 Elite Extreme, Its Next-Gen Laptop Chips

Next Post

Qualcomm’s new Snapdragon 8 Elite Gen 5 will power the next Galaxy and phones that will hear and see everything

Next Post
Qualcomm’s new Snapdragon 8 Elite Gen 5 will power the next Galaxy and phones that will hear and see everything

Qualcomm’s new Snapdragon 8 Elite Gen 5 will power the next Galaxy and phones that will hear and see everything

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Lenovo Yoga Pro 9i 16 Review: A True MacBook Pro Rival?

by Tech Wavo
October 11, 2025
0
Lenovo Yoga Pro 9i 16 Review: A True MacBook Pro Rival?
Computers

We shouldn’t expect any Windows laptop with a powerful discrete GPU to truly replicate what the MacBook Pro does. Yes,...

Read more

The Apple Mac roadmap for 2025 and 2026 may have leaked – through macOS Tahoe 26

by Tech Wavo
October 11, 2025
0
The Apple Mac roadmap for 2025 and 2026 may have leaked – through macOS Tahoe 26
Computers

New MacBooks and Macs are rumored to be incomingThese models are due across 2025 and 2026Almost every Apple computer model...

Read more

A Deal with the Devil? Free VPNs still widespread across the UK

by Tech Wavo
October 11, 2025
0
A Deal with the Devil? Free VPNs still widespread across the UK
Computers

12% of British VPN users still rely on free VPN services, according to a report from NordVPNInstead, general VPN awareness...

Read more

Australia’s March Toward 100 Percent Clean Energy

by Tech Wavo
October 11, 2025
0
Australia’s March Toward 100 Percent Clean Energy
Computers

“ is like 1950s technology—it’s really boring,” Westerman said (“boring,” for grid operators, is the highest form of praise). ​“The...

Read more

Site links

  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use
  • Home
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms of use

No Result
View All Result
  • Home
  • Technology
  • Computers
  • Gadgets
  • Mobile
  • Apps
  • News
  • Financial
  • Stock