Fake OSINT and GPT Utility GitHub Repos Spread PyStoreRAT Malware Payloads

Dec 12, 2025

Cybersecurity researchers are calling attention to a new campaign that’s leveraging GitHub-hosted Python repositories to distribute a previously undocumented JavaScript-based Remote Access Trojan (RAT) dubbed PyStoreRAT.
“These repositories, often themed as development utilities or OSINT tools, contain only a few lines of code responsible for silently downloading a remote HTA file and executing

Get Free Report & Network Analysis

Please check your email for the free report.