What this "Fixed Version" is really doing?

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

A malware campaign is targeting GitHub issue trackers across popular open source projects, including Claude Code's repository. Attackers post fake 'fix' links in issue comments, leading victims to download a ZIP containing a legitimate Windows executable (MPDLP service) bundled with a malicious DLL. Analysis reveals the payload is a multi-stage info stealer (StealC and Vidor) that spawns hidden browser windows to bypass app-bound encryption, exfiltrates credentials, and uses Telegram as a resilient C2 fallback. The campaign spans many projects (Godot, data visualization tools, etc.) and uses newly created GitHub accounts. Defensive recommendations include common-sense URL scrutiny, application allowlisting tools like ThreatLocker, least-privilege access, and zero-trust architecture to limit blast radius from a single compromised endpoint.

11m watch time
14.7K Impressions