Someone Is Faking the GitHub Download Pages of Ledger, TurboTax, Proton, and Claude. We Found the Whole Farm in Our Own Feed.
- Patrick Duggan
- 14 minutes ago
- 4 min read
If you are about to download a piece of software and the link came from a search result or an ad instead of the vendor's own website — stop, and read this first, because there is a good chance you are about to install malware wearing the logo of the exact tool you were looking for.
We run a daily hunt across GitHub that flags accounts impersonating real brands. This week it surfaced a coordinated operation, and once we mapped it against our own indicator data the shape was unmistakable: roughly a hundred throwaway GitHub accounts, each registering one fake organization named after a well-known piece of software, each hosting a profile that points to a poisoned "download." All of it is now in our free threat feed at blocking confidence. Here is who they are impersonating, why the list matters, and how not to become the payload.
The pattern, so you can spot it yourself
The move is simple and it works because it borrows GitHub's credibility. An attacker creates a GitHub organization with a name that looks official — Ledger-Live-Desktop, Trezor-Suite-Api, Proton-VPN-PC, Intuit-TurboTax — and gives it a profile repository (the special .github repo GitHub renders as an org's landing page). That page presents a friendly "Download" button. The real vendor's GitHub org is something else entirely — the genuine Ledger org is LedgerHQ, the genuine Proton is ProtonVPN — but a user who lands on the fake via a search result has no reason to know that. They click, they run an installer, and the installer is a stealer or a wallet drainer.
The tell is always the same: the real download never comes from a GitHub org you found by searching. It comes from the vendor's own domain. If you are on GitHub at all to get consumer software, you are already one step off the safe path.
Who's in the farm — and who should be paying attention
We ranked the targets by how much infrastructure the farm staged against each name, because volume is the signal for who is being worked hardest right now:
Crypto wallets — the heaviest cluster. Ledger, Trezor, Exodus, Chainlist, and a batch of generic "wallet" orgs. This is a wallet-drainer operation first and foremost. If you use a hardware wallet, your seed phrase is the prize, and a fake Ledger Live or Trezor Suite installer is how they go for it.
The Intuit stack — staged early for tax season. QuickBooks appears four times (Self-Employed, Solopreneur, Time-Tracking, plus a fake Webgility integration), TurboTax twice, alongside Synder. Small businesses and self-filers are the mark, and the fact that this is already staged in July tells you they are building the net before the fish arrive.
Security software — the cruel irony tier. ProtonVPN (three orgs), Norton (two), McAfee, and Malwarebytes/AdwCleaner. People actively trying to protect themselves, searching for a security tool, handed malware instead.
Claude — the third time this week. Fake claude-desktop installers. We have now watched an attacker spend the Anthropic name three separate times in seven days across unrelated campaigns. When a brand becomes a lure this fast, that is itself a signal about where user trust is concentrating.
Developer and IT tools. KeePass and KeePassXC, MobaXterm, DBeaver, GeForce NOW. The audience here is technical users who download utilities constantly and are used to grabbing them from odd places — which is exactly the habit being exploited.
What to do
Users: get software from the vendor's domain, never from a search-result GitHub org. Bookmark the real download page. If you must use GitHub, verify the org is the real one — check its age, its star count, and whether it is the same org the vendor links from their own site. A brand-new org with a single profile repo and a download button is a trap.
Especially for crypto and money tools: a hardware-wallet app or accounting software you found through an ad is the highest-risk download you can make right now. Slow down on those specifically.
Brands: your GitHub namespace is being squatted, and you can act on it. GitHub's trademark and impersonation policies allow you to report and reclaim orgs using your name. The farm is built to survive takedowns — a hundred disposable accounts, one repo each, so removing ten does not stop it — but reporting raises the cost and shortens each fake's lifespan. If your brand is on the list above, assume there are more than we caught.
Why this is in our feed and not just this post
Every one of these hundred-odd indicators is in our free STIX feed and blocklists at conf 80 or higher, tagged to the brand being impersonated, so a defender pulling the feed blocks the whole farm without reading a word of this. That is the point of the exercise: the attacker's mass-production becomes distributed defense. They breed the accounts; we harvest them into indicators anyone can use for free. The farm works for us now.
We would rather the brands on this list hear it from a blog post than from a customer who just lost their wallet. If your name is up there, consider this the heads-up.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
