Fake Reputation Now Sells Crypto Malware

The lure is no longer just a shady download. This campaign sells trust first, using fake stars, ratings, views, and “safe” comments to make crypto tools look vetted on GitHub, SourceForge, YouTube, and VirusTotal before the payload ever runs. Check Point ties the operation to a WordPress phishing site, public code-hosting projects, a YouTube promo channel, and reputation abuse on VirusTotal. The payloads are Rust-based clipboard hijackers for Windows and macOS that watch for wallet addresses and swap in attacker-controlled ones, with the campaign aimed at Solana traders, crash-game gamblers, and other users chasing quick-profit tools. The risk is broader than this one clipboard stealer. Once attackers can manufacture trust across popular platforms, the same distribution model can carry stealer or ransomware payloads under a believable reputation trail.

Part of the PlainSec briefing for 2026-06-20

Sources