Someone pretending to be the original credspray is spreading malware

#1 · closed · 2 comments

View on GitHub ↗

salvoM

Hello there, Thanks for the tool, neat idea. I read about it on reddit and when i was googling to find it back I bumped into this: https://github.com/adienamgfrh/CredSpray This seems like a malicious repo trying to spread malware using credspray name. I've reported it and kindly ask you to do the same. PS: Gemini suggested that repo and not yours for some reason, see below. <img width="826" height="305" alt="Image" src="https://github.com/user-attachments/assets/f67ed026-2279-4b98-80af-6abfa5f5ce8d" />

Comments

strikoder

Thanks for reporting it, I really appreciate it! I’ve already submitted a report to GitHub as well. From what I can see, they copied the repository together with the Git history/commits instead of forking it normally, which is why my GitHub account appears in the contributors list even though I have absolutely no involvement with that repository or its zips. Because the copied repository is still being actively updated/committed to (on a daily basis with +700 commits already), search engines and AI systems may pick it up and rank/suggest it higher in some cases, which is likely why google showed that repository instead of the original one. For anyone reading this issue: the only official repository is: https://github.com/strikoder/CredSpray Please avoid downloading binaries or ZIP files from unofficial mirrors/reuploads. Thanks again man for reporting this & wish you happy (ethical xD) hacking!

strikoder

Good news: the malicious repository and the associated account have now been removed by GitHub. I really appreciate everyone who reported it. <img width="1163" height="265" alt="Image" src="https://github.com/user-attachments/assets/20146cd2-b8f7-44f5-8188-18a3b4589a8c" />