TroyDen's Lure Factory GitHub Trojanized package campaign
Campaign
Summary
Hide ▲
Show ▼
The TroyDen's Lure Factory campaign is distributing 300+ Trojanized GitHub packages, broadening supply-chain risk for developers, gamers, and the general public. One of the main lures impersonates an OpenClaw Docker deployer, while other packages masquerade as a Telegram phone tracker, Fishing Planet cheat, Roblox scripts, crypto bots, and VPN crackers. The payload is a LuaJIT-based Trojan with credential-theft and data-exfiltration capability, and two lures remained active after GitHub was notified on March 20.
Related Happenings
GitHub fake-repository infostealer campaign
Campaign
H score41
First: 14.07.2026 22:15
Last: 14.07.2026 22:15
Sources 1
About this happening:
A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
GitHub fake-repository infostealer campaign
CampaignAbout this happening: A GitHub impersonation campaign is distributing infostealer malware through 292 fake repositories, expanding the risk to users searching for trusted software downloads...
Lucide proxy npm packages browser DDoS botnet
Malware Activity
H score31
First: 14.07.2026 10:08
Last: 14.07.2026 10:08
Sources 1
About this happening:
A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Lucide proxy npm packages browser DDoS botnet
Malware ActivityAbout this happening: A 148-package npm campaign turned visitor browsers into a distributed denial-of-service botnet, turning ordinary proxy-page visits into attack traffic. The browser payload...
Deadcode09284814 malicious npm packages delivering Phantom Bot and infostealers
Malware Activity
H score22
First: 18.05.2026 11:57
Last: 18.05.2026 11:57
Sources 1
About this happening:
Four npm packages published by deadcode09284814 were found delivering information-stealing malware and Phantom Bot DDoS capability, putting installers at risk of *...
Deadcode09284814 malicious npm packages delivering Phantom Bot and infostealers
Malware ActivityAbout this happening: Four npm packages published by deadcode09284814 were found delivering information-stealing malware and Phantom Bot DDoS capability, putting installers at risk of *...
OpenClaw/OpenShell managed sandbox backend Claw Chain (multiple vulnerabilities)
Vulnerability
H score31
First: 15.05.2026 16:35
Last: 15.05.2026 16:35
Sources 1
About this happening:
Researchers disclosed four OpenClaw flaws in the OpenShell managed sandbox backend that can be chained for data theft, privilege escalation, and persistence. T...
OpenClaw/OpenShell managed sandbox backend Claw Chain (multiple vulnerabilities)
VulnerabilityAbout this happening: Researchers disclosed four OpenClaw flaws in the OpenShell managed sandbox backend that can be chained for data theft, privilege escalation, and persistence. T...
Mini Shai-Hulud supply-chain campaign targeting npm and PyPI
Campaign
H score45
First: 12.05.2026 17:45
Last: 12.05.2026 17:45
Sources 1
About this happening:
The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environmen...
Mini Shai-Hulud supply-chain campaign targeting npm and PyPI
CampaignAbout this happening: The Mini Shai-Hulud supply-chain campaign linked to TeamPCP expanded into downstream victim reporting, including Grafana Labs. Grafana said its GitHub environmen...
Latest development: 21.05.2026 11:00
Grafana Labs said its GitHub environment was accessed and its codebase downloaded, with additional internal operational information taken from GitHub repositories, after compromise linked to the Mini Shai-Hulud campaign and TanStack npm packages. Grafana said it first spotted malicious activity on May 11, discovered the unauthorized download on May 17, and after contact from the ransom gang rotated automation tokens, enabled enhanced monitoring, audited commits since the May 11 incident, and hardened its GitHub security posture, while saying there is no indication customer production systems or operations were compromised.
Timeline
-
24.03.2026 16:59 1 articles · 3mo ago
Netskope notifies GitHub about malicious repositories
Mitigation Patch UpdateNetskope informed GitHub on March 20, 2026 about malicious GitHub projects and related packages tied to TroyDen's Lure Factory, and two lure repositories still remained active on the platform: Fishing Planet Cheat Menu and phone-number-location-tracking-tool.
Show sources
- GitHub 'OpenClaw Deployer' Repo Delivers Trojan Instead — www.darkreading.com — 24.03.2026 16:59
-
24.03.2026 16:59 2 articles · 3mo ago
Netskope identifies TroyDen's Lure Factory and its LuaJIT Trojan
Technical Analysis UpdateNetskope Threat Labs identified TroyDen's Lure Factory as a widespread GitHub supply-chain campaign using more than 300 Trojanized packages to pose as an OpenClaw Docker deployer and other lures for developers, gamers, and the general public. The malicious repository used a polished README, the real upstream repository, and a github.io page to appear authentic, while the LuaJIT-based payload combined a renamed Lua runtime with an encrypted script, captured screenshots, performed victim geolocation, exfiltrated data to a Frankfurt C2 server, and included credential-theft capabilities.
Show sources
- GitHub 'OpenClaw Deployer' Repo Delivers Trojan Instead — www.darkreading.com — 24.03.2026 16:59
- GitHub 'OpenClaw Deployer' Repo Delivers Trojan Instead — www.darkreading.com — 24.03.2026 16:59