Morphisec Threat Labs has uncovered a coordinated malware campaign hiding in plain sight on GitHub. Dormant accounts were reactivated, polished “AI-built” repos were published, and after they gained traction, attackers quietly injected a previously undocumented backdoor: PyStoreRAT.
PyStoreRAT isn’t just another loader. It profiles systems, deploys multiple payloads, alters execution paths when EDR tools like CrowdStrike Falcon are detected, and uses rotating C2 nodes for persistence.
PyStoreRAT: A New AI-Driven Supply Chain Malware Campaign Targeting IT & OSINT Professionals
PyStoreRAT is redefining supply chain malware with AI-generated GitHub repos. Read the overview and get the full intelligence report.

