On April 24, 2026, within hours of the DeepSeek V4 launch, attackers had created a fake GitHub repository spoofing DeepSeek V4 to deliver malware. Within four hours, victims were downloading malware… | Microsoft Threat Intelligence
On April 24, 2026, within hours of the DeepSeek V4 launch, attackers had created a fake GitHub repository spoofing DeepSeek V4 to deliver malware. Within four hours, victims were downloading malware associated with Vidar infostealer and GhostSocks proxy malware. GitHub promptly took down the malicious repository, organization, and user account to prevent further harm.
The activity relied on impersonation tactics to appear legitimate. The repository copied public benchmark data from the official release, used search-optimized naming and tags, and copied official branding. The attackers structured the fake repository to be discoverable for search queries related to DeepSeek V4.
This was a campaign that used DeepSeek’s name as a lure, not a compromise of legitimate DeepSeek code or accounts. Upon further investigation, this is not unique to DeepSeek V4; we have identified multiple malware campaigns masquerading as trending AI solutions.
DeepSeek V4 launched via API and had a Hugging Fa
www.linkedin.com
Comments (0)