# crownsandband/ExitLag > The repository poses as an optimization tool but actually distributes a PowerShell script (irm ... | iex) to install a 'cracked' ExitLag. The README contains SEO spam and instructions to bypass antivirus — a typical malicious dropper pattern. - Magnitude: 5.8 out of 10 — Early signal - Stars: 160 total · +176 stars today, ≈ 224 by evening - Star trust: star growth looks organic - Category: Security · Created: 2026-10-01 · Last push: 2026-10-01 - GitHub: https://github.com/crownsandband/ExitLag · Page: https://gitnova.dev/en/r/crownsandband/ExitLag ## Useful for - Study the README as an example of social engineering and SEO spam in repos - Check the ps-ps.cc domain and Loader.ps1 on VirusTotal before running - Block similar irm|iex commands via corporate PowerShell policy ## Why it’s here - 176 stars so far today, about 224 expected by the end of the day. - The repository is 1 day old and already has 160 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - Top new repositories this week: #106. - About 107 forks a day — people are taking the code. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 18 - Issues and pull requests: 0 - Watchers: 0 - Average over the last week: 112 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 12 ## Stars per day, last 6 days (oldest → newest, today is partial) 2026-09-27 … 2026-10-02: 0, 0, 0, 0, 0, 176 ## Spotted in now - Top new repositories this week: #106 ## Similar by description 1. **HallHazeStitch/Easy-Worship** — 5.0 · Early signal · Security · +92 stars today, ≈ 117 by evening The repository poses as a performance optimization and deployment automation suite, but actually distributes a malicious PowerShell script run via irm | iex, with execution-policy bypass and antivirus disabling. Full card: https://gitnova.dev/en/r/HallHazeStitch/Easy-Worship.md 2. **Knotgraenhance/Cinema-4d** — 6.2 · Early signal · Security · +111 stars today, ≈ 141 by evening The repository poses as an optimization suite for Cinema 4D, but actually distributes a PowerShell script that runs a third-party loader via irm | iex and tweaks the registry. The README openly mentions "pre-activated launchers" and… Full card: https://gitnova.dev/en/r/Knotgraenhance/Cinema-4d.md 3. **BreakerCurse/FL-Studio** — 5.7 · Early signal · Security · +179 stars today, ≈ 227 by evening The repository poses as an optimized FL Studio build, but is actually a PowerShell script that downloads and executes a third-party loader from an external domain. The README contains search keywords and instructions for bypassing Windows… Full card: https://gitnova.dev/en/r/BreakerCurse/FL-Studio.md 4. **Bottomfluspeed/SolidWorks-CAD** — 5.8 · Early signal · Security · +168 stars today, ≈ 213 by evening The repository poses as a SolidWorks add-on but actually instructs users to run a third-party PowerShell script for a "pre-activated" install, i.e. it distributes cracked software. Full card: https://gitnova.dev/en/r/Bottomfluspeed/SolidWorks-CAD.md 5. **Shardarcairn12/Discord-Server-Raider** — 6.8 · Early signal · Security · +226 stars today, ≈ 287 by evening The repository poses as a Discord server optimization suite, but is actually a raider tool installed via a PowerShell script from an external domain, with instructions to disable antivirus. Full card: https://gitnova.dev/en/r/Shardarcairn12/Discord-Server-Raider.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-02 17:30 UTC, updated every 30 minutes.