While looking for the latest developments in AI, I was browsing a tracker of trending GitHub repositories. A few repos looked odd: they had gained a lot of stars in a single day and climbed high in the daily rankings. All of them contained just a README.md, with a very similar structure. Turns out: another round of an old trick for spreading malware.
I looked at six repositories, most of which are no longer available as I write this. Others are still around, and new ones keep appearing. Their naming follows a similar pattern:
All of them seem to target people looking for software for a Windows PC. Each README describes the tool supposedly on offer and provides an installation command for the user to run:
The command downloads a PowerShell script and immediately executes its contents. That script contains a Base64-encoded command that downloads and runs another PowerShell script, this time with a specific User-Agent:
I downloaded that script to inspect it. It was considerably longer than the previous one, and this is where things got more interesting.
It used a different domain, true-adam[.]su, and introduced the string that became this article’s title: GREETINGSFROMTHERABBIDSTEAM. This was another User-Agent, used for its requests.
The script downloaded two files: /encrypted/1.zip and /encrypted/7za.exe. The second was the program used to extract the first, with the password 1. It also captured the entire desktop, including multiple monitors, and sent a Base64-encoded PNG screenshot to /screen.php. The script did this twice: once before starting the downloaded program and again near the end.
Meanwhile, the terminal displayed progress bars and messages about checking for updates and initializing components. Those bars were just loops with short, random delays. They did not measure the downloads or extraction.
After attempting to launch the downloaded program, the script printed an error about a missing kernel32.dll, followed by a link to a Microsoft support page. That error was hard-coded. There was no check to see whether the DLL was actually missing. The script also tried to remove its temporary files and clear the PowerShell command history. To someone watching the terminal, it could look like an installer that had simply failed.
The extracted archive contained three files:
At the time of analysis, VirusTotal recognized the Java launcher and runtime, with no detections for either file. The hash of jli.dll was unknown. This could indicate a new or repackaged sample, although an unknown hash alone does not establish that.
The executable’s imports and the DLL’s exports explain how the files fit together. javaw.exe imports functions from jli.dll, and the supplied DLL exposes the expected function names. When the launcher starts, it loads the DLL alongside it. This is DLL sideloading.
Static analysis of the DLL revealed a concealed Windows executable component. Its code contains routines for collecting data from several applications:
Firefox: saved-login and key files, history, cookies, and form history.
Chromium-based browsers: references to login databases, cookies, and encryption keys, although this collection path has not been fully traced.
Discord: stored authentication tokens, including routines to locate and decrypt them.
Steam: account and session-related data.
Roblox: references to stored session cookies, although their processing requires further analysis. Yes, Roblox too.
The DLL’s network code sends data via an HTTPS POST to rabbidscc[.]cc, using the User-Agent oathuadly. The request body has not been fully reconstructed, so the exact mapping between collected data and transmitted fields remains open.
I also wonder how this plays out when an AI assistant does the searching. With tools such as ChatGPT Work, I can imagine asking an agent to find a utility and set it up. I have not tested whether it would install any of these repositories; its permissions and checks matter. But if an agent accepts a README as a trustworthy installation guide, it could follow the same instructions a person would.
A repository containing nothing but a README can still do plenty of damage if someone follows its instructions.