hallbudgieleap/Glary-Utilities-Pro
About the project
The repository poses as Glary Utilities Pro but actually instructs users to run a PowerShell script from an external domain for a "pre-activated" install. This is a typical malware distribution scheme, not a legitimate project.
Useful for
- Avoid running the irm command from the external ps-ps.cc domain on a work machine
- Inspect the repository for supply-chain attack indicators before any use
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 125 stars so far today, about 163 expected by the end of the day.
- The repository is 1 day old and already has 125 stars. With less than two weeks of history, there's no usual pace to compare the spike against yet.
- Top new repositories this week: #129.
- About 177 forks a day — people are taking the code.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 125
- Today
- 125 · ≈ 163 by evening
- Forks
- 17
- Issues and pull requests
- 0
- Watchers
- 0
- Created
- October 1, 2026
- Last push
- October 1, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Spotted in
- October 2, 2026Top new repositories this week: #129
Similar by description
-
5.1
Swifteofight/Autodesk-Revit
The repository poses as an "Optimization Suite" for Autodesk Revit, but actually instructs users to pipe a remote PowerShell script from an external domain to "activate" Revit, bypassing normal installation. This is a…
-
5.7
Bottomfluspeed/SolidWorks-CAD
The repository poses as a SolidWorks add-on but actually instructs users to run a third-party PowerShell script for a "pre-activated" install, i.e. it distributes cracked software.
-
5.7
ashdriverclippers/Microsoft-Visio
The repo poses as a "Microsoft Visio optimization suite", but is actually a PowerShell loader that fetches and executes remote code from ps-ps.cc and tells users to disable antivirus. Signs of a malicious/pirated…
-
5.5
TitanWaspShape35/Kontakt-8
The repository poses as Kontakt 8, but its README describes installing via a PowerShell script from an external domain and disabling antivirus — typical signs of a malicious loader rather than a legitimate project.
-
5.8
surfaceguardianway/Better-Discord
The repository poses as an optimization suite for BetterDiscord, but actually instructs users to pipe a third-party PowerShell script that tweaks the registry and disables Windows protections. It shows signs of a…
-
5.9
CoatDistributorHost/Adobe-Substance-3d
The repository poses as an optimization suite for Adobe Substance 3D, but actually instructs users to run a third-party PowerShell script (irm ... | iex) for a 'pre-activated' install and to bypass antivirus.