The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →ReversingLabs reported on June 18, 2025 that it had identified 67 GitHub repositories impersonating legitimate projects, most presented as Python hacking tools. The copies contained concealed malicious code, but the investigation did not establish how many times the repositories were cloned or how many systems were affected.
What happened in the Banana Squad campaign
The repositories used the same names as benign, legitimate projects, making them appear to be ordinary copies of popular Python security tools. ReversingLabs said the 67 repositories hosted hundreds of trojanized files.
Researchers found the campaign by working backward from malicious URL indicators in their network threat-intelligence data. They then collected repositories with matching names and examined their contents. ReversingLabs attributed the activity to the group it calls Banana Squad, based on similarities in URL structures, concealment methods and encoding patterns seen in earlier campaigns documented by Checkmarx.
Historical timeline
| Date or period | Reported event |
|---|---|
| 2023 | ReversingLabs said Banana Squad’s earlier malicious Python packages accumulated close to 75,000 downloads before identification and removal. |
| June 6, 2025 | A campaign using the hostname 1312services[.]ru was detected, according to the ReversingLabs report. |
| June 18, 2025 | ReversingLabs published its report identifying 67 trojanized GitHub repositories. |
| Before publication on June 18 | GitHub confirmed that all 67 repositories reported by ReversingLabs had been removed by the preceding weekend. |
The hostnames and removal status above describe the June 2025 investigation. They are not a current check of whether those domains or other copies remain active.
#1 Best Overall
How the malicious code was hidden
The central trick was visual rather than sophisticated: attackers appended a large amount of whitespace after an apparently legitimate line of source code, then placed additional code far to the right. In a normal editor or narrow browser view, the harmful content could sit beyond the visible line width. A quick glance therefore showed code that looked authentic while concealing what would execute.
Encoding and encryption variations
ReversingLabs found several combinations of obfuscation in the trojanized files:
Rank #2
- Base64-encoded content
- Hexadecimal-encoded content
- Fernet-encrypted content
- Long-line whitespace used to push payload code off-screen
These techniques can appear separately or together. Base64 and hexadecimal are encodings, not encryption; they can make text less readable but are reversible. Fernet is an encryption format. Regardless of the format, the practical warning is the same: visible source at the left edge of a file is not proof that the entire line is benign.
Signs that a repository may be an impersonator
ReversingLabs described several campaign-specific clues. None is conclusive by itself, and the indicators belong to this historical campaign rather than a universal GitHub detection rule.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Rank #3
- Several suspicious accounts had only one repository.
- Repository “About” text appeared optimized for search and included emojis.
- Files contained dynamically generated strings.
- A project had the expected name but lacked the normal history, maintainers or surrounding documentation associated with the genuine upstream project.
- Source lines were unusually long, with large blank areas before trailing code.
- Files contained unexpected Base64, hexadecimal or Fernet material in places where a tool would not normally need it.
The report identified dieserbenni[.]ru as the primary hostname associated with the campaign and also discussed 1312services[.]ru. Treat these as historical indicators from the report, not as evidence that the domains are still operating.
What developers should do before cloning or running code
1. Confirm the intended upstream
Start from the project’s official documentation, organization page or another trusted reference instead of relying only on GitHub search results. Check the owner, repository history, release process, issue activity and links from the project’s established channels. Identical names do not establish identical provenance.
Rank #4
- Craft Supplies
2. Compare with a known-good version
ReversingLabs’ stated recommendation was to compare the desired repository with a previous, known-good version of the software or source code. Obtain that reference from a trusted checkout, release archive or verified organizational source, then compare files and commits rather than reviewing only the first screen of each file.
3. Make hidden content visible
- Enable horizontal scrolling or wrap long lines in the editor.
- Search for unusually long lines and trailing whitespace.
- Inspect the complete file, including text beyond the normal display width.
- Search for decoding and decryption calls and trace where their output is executed.
- Review startup scripts, installation hooks, shell commands and network requests before running the project.
4. Isolate execution
If a project must be tested, use a disposable virtual machine or container with no personal credentials, SSH keys, cloud tokens or production network access. Treat installation scripts and package setup steps as executable code, not as harmless project plumbing.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsBest Value
5. Preserve evidence if you find a copy
Record the repository owner, name, commit identifier, file paths and relevant indicators before reporting it to GitHub or your security team. Do not execute suspicious files merely to confirm that they are malicious.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is known—and what is not
| Question | What the June 2025 reporting established |
|---|---|
| How many repositories were identified? | 67 repositories. |
| What did they imitate? | Legitimate repositories, most presented as Python hacking tools. |
| Were they removed? | ReversingLabs said GitHub confirmed removal of all 67 by the weekend before June 18, 2025. |
| How many clones were made? | Unknown; the investigators said they did not know. |
| How many victims or infections occurred? | No verified victim or infection count was provided. |
| Are the domains still active? | Not established by the historical report. |
Why broader open-source risk still matters
ReversingLabs, as reported by Dark Reading on June 20, 2025, said malicious-package detections on npm, PyPI and RubyGems fell 70% from 2023 to 2024, while leaked software-development secrets on those registries rose 12%. Those figures apply only to the named package platforms and the cited comparison; they are not GitHub statistics or a measure of all open-source risk.
Robert Simmons, a ReversingLabs principal malware researcher, said: “As a result of the community catching on, threat actors are developing less-noticeable techniques in the hopes of staying hidden longer.” He also cautioned that “this isn’t to say that OSS risk is declining in general, and incidents of malicious OSS package discoveries still happen on a weekly, if not daily basis,” according to the same Dark Reading coverage.
Tools and comparison approaches
The reporting does not establish interchangeable consumer products or a product benchmark. It does identify three practical review dimensions:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11- Provenance: Is this the intended upstream repository and owner?
- Visibility: Does inspection expose content hidden beyond normal line width or behind encoding?
- Version integrity: Can the current copy be compared with a trusted, known-good version?
ReversingLabs discussed its Spectra Assure differential-analysis capabilities in connection with the investigation. That is the vendor’s description of its tooling, not an independent comparative evaluation.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

