Skip to main content
AVOID.NET

Rust Crypto Clipper Malware — Fake GitHub Stars Campaign

avoid.net/rust-crypto-clipper-malware-fake-github-stars-campaign0/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·52DerZ…HFgG

Summary

An active malware campaign discovered by Check Point Research in June 2026 distributes a Rust-based cryptocurrency clipboard hijacker for Windows and macOS disguised as crypto trading tools and gambling predictors. The operation manufactured false legitimacy through coordinated fake GitHub star networks, AI-narrated YouTube tutorials, inflated VirusTotal ratings, and a SourceForge page showing over 44,000 downloads, achieving more than 5,000 confirmed genuine GitHub downloads. The clipper silently replaces copied wallet addresses with attacker-controlled addresses drawn from an embedded list of over 15,500 addresses, primarily Bitcoin.

Connected Entities

9 entities · 60 linked investigations
Organizations
Ethereum64Cardano72Solana62Rust Crypto Clipper Malware — Fake GitHub Stars CampaignMonero58
Tokens
Relationships
  • Rust Crypto Clipper Malware — Fake GitHub Stars Campaignmentioned withBitcoin(70%)
  • Rust Crypto Clipper Malware — Fake GitHub Stars Campaignmentioned withDogecoin(60%)
  • Rust Crypto Clipper Malware — Fake GitHub Stars Campaignmentioned withEthereum(60%)
  • Rust Crypto Clipper Malware — Fake GitHub Stars Campaignmentioned withLitecoin(60%)
  • Rust Crypto Clipper Malware — Fake GitHub Stars Campaignmentioned withCardano(60%)
  • Rust Crypto Clipper Malware — Fake GitHub Stars Campaignmentioned withSolana(60%)
  • Rust Crypto Clipper Malware — Fake GitHub Stars Campaignmentioned withMonero(60%)
  • Ethereummentioned withBitcoin(60%)
  • Moneromentioned withBitcoin(60%)
  • Litecoinmentioned withBitcoin(70%)
  • + 10 more
Have evidence about Rust Crypto Clipper Malware — Fake GitHub Stars Campaign?

Timeline(7 events)

2019

Threat actor operating under the handle '@JoseCmanXD' first identified as active on a hacking forum. Exact date within 2019 not specified in public reporting.

Check Point Research

July 2020

YouTube channel later used to promote the malware campaign was created. Exact date within July 2020 not specified.

Check Point Research

2022

Actor '@JoseCmanXD' posted thread on a hacking forum titled 'BLACKHAT | Bitcoin Stealer | Advanced Builder | Tutorial | Clipper [Address Changer]+Re-Fud method,' sharing a malicious crypto-related tool. Exact date within 2022 not specified.

Check Point Research

27 April 2026

Coordinated promotional articles promoting the malicious tools were published simultaneously across multiple legitimate news websites, distributed via EIN Presswire and syndicated to USA TODAY Network partner outlets.

Check Point Research

18 June 2026

GBHackers and Infosecurity Magazine publish coverage of the campaign based on Check Point findings.

Infosecurity Magazine

19 June 2026

Check Point Research publishes full technical report 'From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker,' disclosing the campaign with indicators of compromise. Help Net Security also publishes coverage.

Check Point Research

19 June 2026

The Hacker News and Cybersecurity News publish coverage of the campaign, expanding public awareness of the malicious GitHub accounts, SourceForge page, and YouTube channel.

The Hacker News
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (1 event). 7 of 7 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 6/21/2026, 5:33:05 PM

last updated: 7/27/2026, 2:04:33 AM

3 views

avoid.net — verified advice for a post-truth world