malware nuget

gta5rp-x-x

discovered 2026-07-14

NuGet DotnetTool downloader ("GTA5RP") published under operator pepegit666. Assembly gta5rp.dll, release tag "gta5rp.com". Wraps gtaobus.pyc with pyarmor_runtime_015050; falls back to a hardcoded authenticated HTTP proxy for Google Sheets when direct access fails. On run it masquerades with a colored Russian console, sets AWS-style env vars, DoH-resolves GitHub hosts, and fetches the shared second-stage pepesoft.exe (Hugging Face -> GitHub Releases -> dormant BitTorrent). The payload writes host telemetry/inventory to Google Sheets and enforces an HWID/UUID ban-list kill switch. The GTA5RP product sheet also hosts the shared `banned` worksheet used by every payload. Only the [email protected] version was explicitly disclosed; other package versions were not enumerated in the source.

Threat types

data_exfiltration c2_agent

Malicious versions

  • unspecified

Campaigns

Indicators

Read the full analysis →