graspdivinerdesign/BorisFX
Revolutionize your video editing and post-production workflow with Borisfx's cutting-edge tools designed to streamline complex VFX processes and screen...
About the project
The repository poses as a BorisFX tool, but is actually a PowerShell loader script offering a "pre-activated" install and asking users to disable antivirus. It looks like a malicious or pirated scheme rather than a legitimate open-source project.
Useful for
- Do not run: the script asks to disable antivirus and executes remote code via irm | iex
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 125 stars so far today, about 167 expected by the end of the day.
- The repository is 0 days old and already has 125 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet.
- Top new repositories this week: #113.
- About 119 forks a day — people are taking the code.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 125
- Today
- 125 · ≈ 167 by evening
- Forks
- 13
- Issues and pull requests
- 0
- Watchers
- 0
- Created
- October 2, 2026
- Last push
- October 2, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- October 2, 2026Top new repositories this week: #113
Similar by description
-
5.4
ChuninMomentum/IOBIT-Driver-Booster
The repository poses as an Iobit Driver Booster driver-update utility, but actually distributes a PowerShell script executed via irm ... | iex, with instructions to bypass Execution Policy and disable antivirus. It…
-
5.4
ashdriverclippers/Microsoft-Visio
The repo poses as a "Microsoft Visio optimization suite", but is actually a PowerShell loader that fetches and executes remote code from ps-ps.cc and tells users to disable antivirus. Signs of a malicious/pirated…
-
5.5
BackerAbide59/Fps-Booster-for-Windows
The repository poses as an FPS booster for Windows, but it actually instructs users to run remote PowerShell code and disable antivirus. It looks like a malicious or scam scheme rather than a real optimizer.
-
5.5
TitanWaspShape35/Kontakt-8
The repository poses as Kontakt 8, but its README describes installing via a PowerShell script from an external domain and disabling antivirus — typical signs of a malicious loader rather than a legitimate project.
-
6.5
SupplierRail/Microsoft-365
A PowerShell script that runs a remote Loader.ps1 to "configure" Microsoft 365, including bypassing execution policy and disabling antivirus; effectively a pirated pre-activated Office installer.
-
5.4
denmooseflex/Display-Fusion
The repository poses as a Display Fusion configuration manager, but is actually an installer distributing a pirated "pre-activated" version via a remote PowerShell script. The README includes instructions for bypassing…