
This isnât just any malware campaignâitâs a masterclass in deception. The attackers have set up a fake project on SourceForge called âofficepackage,â which, letâs be honest, sounds about as exciting as a PowerPoint presentation on tax law. But donât be fooled! This project is a wolf in sheepâs clothing, designed to look like Microsoft Office add-ins copied from GitHub. The real kicker? Its auto-generated subdomain, âofficepackage.sourceforge.io,â which search engines like Russiaâs Yandex happily picked up. Users who visited the page were greeted with a fake list of office apps and download buttons that, surprise, started the malware infection. đ