GitHub is rapidly becoming the go-to platform for sharing software. Originally built for developers to collaborate on code, it now hosts millions of projects ranging from hobby scripts to widely used applications. That popularity, however, has also made it an attractive delivery platform for cybercriminals.

For most home users, GitHub is not something you need to use in your daily life. You might encounter it when searching for a tool, following installation instructions, or trying out something recommended on a forum or social media. And that’s where the risk begins. GitHub is not an app store. It does not check every repository for safety, and anyone can upload code, including cybercriminals.

Recent campaigns highlight how this can be abused. We’ve seen cybercriminals create convincing repositories that impersonate well-known brands like Malwarebytes and LastPass, offering downloads that are anything but legitimate. In other cases, hundreds of repositories have been spun up to distribute Trojanized versions of popular software. These pages often look polished, include documentation, and even fake user engagement to appear trustworthy.

We’ve also seen campaigns targeting specific groups, including retro-gamers, people looking for free AI agents, OpenClaw users, and people searching for AppleCare+ service.