Mr. Titus Tech is correct. cpuid-dot-com is indeed delivering malware right now.
As I began poking this with I stick I discovered this is not your typical run-of-the-mill malware. This malware is deeply trojanized, distributes from a compromised domain (cpuid-dot-com), performs file masquerading, is multi-staged, operates (almost) entirely in-memory, and uses some interesting methods to evade EDRs and/or AVs such as proxying NTDLL functionality from a .NET assembly.
The C2 domain present in one of the binaries is a clear IoC. This is the same Threat Group who was masquerading FileZilla in early March, 2026. They've been busy.
Can't get your eyes off the new #XIAORP2350? To celebrate the launch, we're #Giveaway 5 units for you to experience the power of @RaspberryPi_org RP2350.
To enter:
1️⃣ Follow @seeedstudio
2️⃣❤️ & Retweet with #XIAORP2350
We'll pick 5 winners on Aug. 14th! Good luck! 🍀
Discover more: https://t.co/EEL3ZjO16l
With the #GhostWrite CPU vulnerability, all isolation boundaries are broken - sandbox/container/VM can't prevent GhostWrite from writing and reading arbitrary physical memory on affected RISC-V CPUs. Deterministic, fast, and reliable - no side channels. https://t.co/qtmosPvuYl