# NavigatorWeb/Autodesk-CFD > A PowerShell script that uses irm | iex to download and run an installer from an external site, promising to "activate" Autodesk CFD and advising users to disable antivirus. In practice it is an obfuscated loader, not a CFD tool. - Magnitude: 5.6 out of 10 — Early signal - Stars: 121 total · +121 stars today, ≈ 158 by evening - Star trust: star growth looks organic - Category: Security · Created: 2026-10-01 · Last push: 2026-10-01 - GitHub: https://github.com/NavigatorWeb/Autodesk-CFD · Page: https://gitnova.dev/en/r/NavigatorWeb/Autodesk-CFD ## Useful for - Inspect the repository in a sandbox to confirm it is a malicious loader - Document the irm | iex attack pattern for security awareness training ## Why it’s here - 121 stars so far today, about 158 expected by the end of the day. - The repository is 1 day old and already has 121 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - Top new repositories this week: #138. - About 138 forks a day — people are taking the code. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 17 - Issues and pull requests: 0 - Watchers: 0 - Average over the last week: 79 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 0 ## Stars per day, last 6 days (oldest → newest, today is partial) 2026-09-27 … 2026-10-02: 0, 0, 0, 0, 0, 121 ## Spotted in now - Top new repositories this week: #138 ## Similar by description 1. **PassMediator/Adobe-Audition** — 5.6 · Early signal · Security · +125 stars today, ≈ 163 by evening A PowerShell script that uses irm | iex to fetch and run an installer from the external site ps-ps.cc, promising to "activate" Adobe Audition and bypass protection. The README shows typical malware-dropper signs: Execution Policy bypass,… Full card: https://gitnova.dev/en/r/PassMediator/Adobe-Audition.md 2. **TitanWaspShape35/Kontakt-8** — 5.5 · Early signal · Security · +101 stars today, ≈ 132 by evening The repository poses as Kontakt 8, but its README describes installing via a PowerShell script from an external domain and disabling antivirus — typical signs of a malicious loader rather than a legitimate project. Full card: https://gitnova.dev/en/r/TitanWaspShape35/Kontakt-8.md 3. **Swifteofight/Autodesk-Revit** — 5.1 · Early signal · Security · +79 stars today, ≈ 103 by evening The repository poses as an "Optimization Suite" for Autodesk Revit, but actually instructs users to pipe a remote PowerShell script from an external domain to "activate" Revit, bypassing normal installation. This is a classic… Full card: https://gitnova.dev/en/r/Swifteofight/Autodesk-Revit.md 4. **DelugeWalrus/Autodesk-Inventor** — 5.3 · Early signal · Other · +86 stars today, ≈ 112 by evening The repository distributes a "pre-activated" version of Autodesk Inventor via a PowerShell script downloaded from an external domain. The README only covers installation and bypassing Windows protections, not actual code. Full card: https://gitnova.dev/en/r/DelugeWalrus/Autodesk-Inventor.md 5. **graspdivinerdesign/BorisFX** — 6.2 · Early signal · Security · +125 stars today, ≈ 163 by evening The repository poses as a BorisFX tool, but is actually a PowerShell loader script offering a "pre-activated" install and asking users to disable antivirus. It looks like a malicious or pirated scheme rather than a legitimate open-source… Full card: https://gitnova.dev/en/r/graspdivinerdesign/BorisFX.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-02 16:40 UTC, updated every 30 minutes.