# Swifteofight/Autodesk-Revit > The repository poses as an "Optimization Suite" for Autodesk Revit, but actually instructs users to pipe a remote PowerShell script from an external domain to "activate" Revit, bypassing normal installation. This is a classic malware-distribution pattern disguised as a crack. - Magnitude: 5.1 out of 10 — Early signal - Stars: 79 total · +79 stars today, ≈ 103 by evening - Star trust: star growth looks organic - Category: Security · Created: 2026-10-01 · Last push: 2026-10-01 - GitHub: https://github.com/Swifteofight/Autodesk-Revit · Page: https://gitnova.dev/en/r/Swifteofight/Autodesk-Revit ## Useful for - Avoid running it: the irm ... | iex command executes arbitrary code from a third-party server - Audit the repo for supply-chain attack indicators before any use ## Why it’s here - 79 stars so far today, about 103 expected by the end of the day. - The repository is 1 day old and already has 79 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - About 118 forks a day — people are taking the code. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 9 - Issues and pull requests: 0 - Watchers: 0 - Average over the last week: 52 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 0 ## Stars per day, last 6 days (oldest → newest, today is partial) 2026-09-27 … 2026-10-02: 0, 0, 0, 0, 0, 79 ## Similar by description 1. **hallbudgieleap/Glary-Utilities-Pro** — 5.6 · Early signal · Security · +125 stars today, ≈ 163 by evening The repository poses as Glary Utilities Pro but actually instructs users to run a PowerShell script from an external domain for a "pre-activated" install. This is a typical malware distribution scheme, not a legitimate project. Full card: https://gitnova.dev/en/r/hallbudgieleap/Glary-Utilities-Pro.md 2. **denmooseflex/Display-Fusion** — 5.7 · Early signal · Security · +148 stars today, ≈ 193 by evening The repository poses as a Display Fusion configuration manager, but is actually an installer distributing a pirated "pre-activated" version via a remote PowerShell script. The README includes instructions for bypassing Execution Policy… Full card: https://gitnova.dev/en/r/denmooseflex/Display-Fusion.md 3. **Bottomfluspeed/SolidWorks-CAD** — 5.7 · Early signal · Security · +129 stars today, ≈ 168 by evening The repository poses as a SolidWorks add-on but actually instructs users to run a third-party PowerShell script for a "pre-activated" install, i.e. it distributes cracked software. Full card: https://gitnova.dev/en/r/Bottomfluspeed/SolidWorks-CAD.md 4. **surfaceguardianway/Better-Discord** — 5.8 · Early signal · Security · +172 stars today, ≈ 224 by evening The repository poses as an optimization suite for BetterDiscord, but actually instructs users to pipe a third-party PowerShell script that tweaks the registry and disables Windows protections. It shows signs of a typical malicious/pirated… Full card: https://gitnova.dev/en/r/surfaceguardianway/Better-Discord.md 5. **PassMediator/Adobe-Audition** — 5.6 · Early signal · Security · +125 stars today, ≈ 163 by evening A PowerShell script that uses irm | iex to fetch and run an installer from the external site ps-ps.cc, promising to "activate" Adobe Audition and bypass protection. The README shows typical malware-dropper signs: Execution Policy bypass,… Full card: https://gitnova.dev/en/r/PassMediator/Adobe-Audition.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-02 16:40 UTC, updated every 30 minutes.