crownsandband/ExitLag
About the project
The repository poses as an optimization tool but actually distributes a PowerShell script (irm ... | iex) to install a 'cracked' ExitLag. The README contains SEO spam and instructions to bypass antivirus — a typical malicious dropper pattern.
Useful for
- Study the README as an example of social engineering and SEO spam in repos
- Check the ps-ps.cc domain and Loader.ps1 on VirusTotal before running
- Block similar irm|iex commands via corporate PowerShell policy
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 136 stars so far today, about 177 expected by the end of the day.
- The repository is 1 day old and already has 126 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet.
- Top new repositories this week: #126.
- About 106 forks a day — people are taking the code.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 126
- Today
- 136 · ≈ 178 by evening
- Forks
- 13
- Issues and pull requests
- 0
- Watchers
- 0
- Created
- October 1, 2026
- Last push
- October 1, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- October 2, 2026Top new repositories this week: #126
Similar by description
-
5.0
HallHazeStitch/Easy-Worship
The repository poses as a performance optimization and deployment automation suite, but actually distributes a malicious PowerShell script run via irm | iex, with execution-policy bypass and antivirus disabling.
-
6.2
Knotgraenhance/Cinema-4d
The repository poses as an optimization suite for Cinema 4D, but actually distributes a PowerShell script that runs a third-party loader via irm | iex and tweaks the registry. The README openly mentions "pre-activated…
-
5.5
BreakerCurse/FL-Studio
The repository poses as an optimized FL Studio build, but is actually a PowerShell script that downloads and executes a third-party loader from an external domain. The README contains search keywords and instructions…
-
5.7
Bottomfluspeed/SolidWorks-CAD
The repository poses as a SolidWorks add-on but actually instructs users to run a third-party PowerShell script for a "pre-activated" install, i.e. it distributes cracked software.
-
6.7
Shardarcairn12/Discord-Server-Raider
The repository poses as a Discord server optimization suite, but is actually a raider tool installed via a PowerShell script from an external domain, with instructions to disable antivirus.
-
5.5
TitanWaspShape35/Kontakt-8
The repository poses as Kontakt 8, but its README describes installing via a PowerShell script from an external domain and disabling antivirus — typical signs of a malicious loader rather than a legitimate project.