# graspdivinerdesign/BorisFX > The repository poses as a BorisFX tool, but is actually a PowerShell loader script offering a "pre-activated" install and asking users to disable antivirus. It looks like a malicious or pirated scheme rather than a legitimate open-source project. - Magnitude: 6.2 out of 10 — Early signal - Stars: 125 total · +125 stars today, ≈ 163 by evening - Star trust: star growth looks organic - Category: Security · Created: 2026-10-02 · Last push: 2026-10-02 - GitHub: https://github.com/graspdivinerdesign/BorisFX · Page: https://gitnova.dev/en/r/graspdivinerdesign/BorisFX ## Useful for - Do not run: the script asks to disable antivirus and executes remote code via irm | iex ## Why it’s here - 125 stars so far today, about 163 expected by the end of the day. - The repository is 0 days old and already has 125 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet. - Top new repositories this week: #130. - About 119 forks a day — people are taking the code. ## Star trust Star growth looks organic. Star-trust labels are heuristics based on the repository’s behavior, not a check of every stargazer. ## Numbers - Forks: 13 - Issues and pull requests: 0 - Watchers: 0 - Average over the last week: 163 per day - Usual pace: too little history (under two weeks) - Stars in the last hour (measured): 0 ## Stars per day, last 6 days (oldest → newest, today is partial) 2026-09-27 … 2026-10-02: 0, 0, 0, 0, 0, 125 ## Spotted in now - Top new repositories this week: #130 ## Similar by description 1. **ChuninMomentum/IOBIT-Driver-Booster** — 5.6 · Early signal · Security · +139 stars today, ≈ 181 by evening The repository poses as an Iobit Driver Booster driver-update utility, but actually distributes a PowerShell script executed via irm ... | iex, with instructions to bypass Execution Policy and disable antivirus. It looks like a malicious… Full card: https://gitnova.dev/en/r/ChuninMomentum/IOBIT-Driver-Booster.md 2. **ashdriverclippers/Microsoft-Visio** — 5.7 · Early signal · Security · +143 stars today, ≈ 187 by evening The repo poses as a "Microsoft Visio optimization suite", but is actually a PowerShell loader that fetches and executes remote code from ps-ps.cc and tells users to disable antivirus. Signs of a malicious/pirated installer rather than a… Full card: https://gitnova.dev/en/r/ashdriverclippers/Microsoft-Visio.md 3. **BackerAbide59/Fps-Booster-for-Windows** — 5.8 · Early signal · Security · +153 stars today, ≈ 200 by evening The repository poses as an FPS booster for Windows, but it actually instructs users to run remote PowerShell code and disable antivirus. It looks like a malicious or scam scheme rather than a real optimizer. Full card: https://gitnova.dev/en/r/BackerAbide59/Fps-Booster-for-Windows.md 4. **TitanWaspShape35/Kontakt-8** — 5.5 · Early signal · Security · +101 stars today, ≈ 132 by evening The repository poses as Kontakt 8, but its README describes installing via a PowerShell script from an external domain and disabling antivirus — typical signs of a malicious loader rather than a legitimate project. Full card: https://gitnova.dev/en/r/TitanWaspShape35/Kontakt-8.md 5. **SupplierRail/Microsoft-365** — 6.6 · Early signal · Security · +183 stars today, ≈ 239 by evening A PowerShell script that runs a remote Loader.ps1 to "configure" Microsoft 365, including bypassing execution policy and disabling antivirus; effectively a pirated pre-activated Office installer. Full card: https://gitnova.dev/en/r/SupplierRail/Microsoft-365.md --- Magnitude (0–10) measures how fast and how unusually interest in a repository is growing right now. It is not a quality score. Days are UTC. “So far today” is a fact; “expected by the end of the day” is a forecast. Summaries and use cases are written by an LLM (DeepSeek V4.1 Flash) from the README and may be inaccurate: verify specific claims (benchmarks, speed, hardware) in the repository itself. Data as of 2026-10-02 16:40 UTC, updated every 30 minutes.