PSA: A possible malware disguised as ComfyUI custom node Claude skills on GitHub

I was looking for some Claude skills to help create a custom node for Comfyui. And I found two:
https://github.com/jtydhr88/comfyui-custom-node-skills
https://github.com/MusfiqurRahma/comfyui-custom-node-skills


And noticed that the second is basically the same as the first even if it' is not a fork, and it's bigger! so I downloaded and checked the zip and found that there is another zip in one of the subfolders with three files:

https://preview.redd.it/456s9di0sx5h1.png?width=667&format=png&auto=webp&s=72dc706827c60e458211ac48503d081e0faf489d

The cmd run "unit.exe packages.txt", and that text files is actually an obfuscated lua(?) script. Moreover, all the links in their newly created/modified README are changed to download this particular inside zip.

I dunno how to report a Github repos, but I'm creating an account now to do it. In the meanwhile, i wanted to warn people from it.

https://redd.it/1tzq7js
@rStableDiffusion
An experiment: recreate JSON-prompted closed model image in Ideogram 4
https://redd.it/1tzr6ci
@rStableDiffusion