New variants of the NFCShare Android malware are being distributed as fake banking app updates hosted on GitHub repositories. The malware targets customers of European banks, primarily in Italy and Spain, by tricking victims into scanning their payment cards near their device's NFC chip via a fake verification screen. It steals card numbers, expiry dates, card types, and 4-digit PINs, exfiltrating data to a C2 server over WebSocket for use in NFC relay payment fraud. Since April 2026, the GitHub repo has hosted 56 unique malicious APKs impersonating banks including Intesa, Banca Sella, Nexi, and CaixaBank. Newer samples also use malformed APK packaging to disrupt automated static analysis tools. Users are advised to install banking apps only from Google Play and enable Play Protect.