Fake GitHub repositories with misleading names are distributing malware through PowerShell commands that execute multi-stage scripts. The attack uses DLL sideloading to deploy a stealer that harvests credentials from browsers, Discord, Steam, and gaming platforms while displaying fake installer progress messages.