GitHub Releases Used to Spread Clipboard-Stealing Trojan

Attackers are exploiting trust in GitHub Releases by wrapping legitimate Proxifier installers with malware that hijacks cryptocurrency clipboard data. This means the infection begins at download, not execution, undermining the usual advice to only install from trusted sources when the trusted source itself is compromised. The malicious release includes a real installer and activation keys to appear legitimate, increasing the chance of user acceptance. Research shows a multi-stage infection chain starting from a GitHub repository hosting a Proxifier-themed release archive. The archive contains a malicious wrapper executable and a text file with activation keys. Once run, the malware disables Microsoft Defender protections for its files and injects a .NET component to manage exclusions. The final payload is ClipBanker, which silently replaces cryptocurrency wallet addresses copied to the clipboard, redirecting payments to attacker-controlled wallets. This campaign highlights how attackers leverage popular developer tools and trusted platforms to bypass security assumptions. Users searching for proxy tools, especially those handling cryptocurrency on the same machine, face a real risk of financial fraud. The threat is not a broad enterprise emergency but a targeted risk for individuals relying on GitHub Releases for software acquisition.

Part of the PlainSec briefing for 2026-04-10

Sources