
This isn’t just any malware campaign—it’s a masterclass in deception. The attackers have set up a fake project on SourceForge called “officepackage,” which, let’s be honest, sounds about as exciting as a PowerPoint presentation on tax law. But don’t be fooled! This project is a wolf in sheep’s clothing, designed to look like Microsoft Office add-ins copied from GitHub. The real kicker? Its auto-generated subdomain, “officepackage.sourceforge.io,” which search engines like Russia’s Yandex happily picked up. Users who visited the page were greeted with a fake list of office apps and download buttons that, surprise, started the malware infection. 🎁