A campaign beginning in late June 2026 built hundreds of fake brand repositories on GitHub and used SEO to place them at the top of software download searches.
Researchers logged 7.4 million infected devices between January and June 2026 — a 27% jump — as the infostealer market matured into a fully automated criminal supply chain.