The desktop app that never existed
Three of the largest payroll and HR platforms in the United States have one thing in common: none of them makes a Windows desktop app. Somebody built one for each of them anyway.
Allure Security published the findings on 24 September. The lure pages were generated with Lovable, an AI tool that turns a sentence into a web page, hosted on Vercel behind a bot-challenge screen, with the download button pointing at a release file in a GitHub repository. One account, one repository per brand, the same 64 MB installer published three times under three different names. Run it and a genuine Microsoft .NET Runtime installer appears on screen while ConnectWise ScreenConnect goes in underneath as a Windows service, configured with every visible sign switched off: no banner, no tray icon, no notice when somebody connects. It survives a restart, starts before anyone signs in, and runs in Safe Mode.
ScreenConnect is a legitimate product that real IT departments use every day, which is precisely why it was chosen. GitHub counted around 291 downloads, researchers included, and only 32 of 70 scanning engines flagged the file at first. Everything reported back to a single relay in Germany. Allure has since had the pages, the domain and the repositories taken down.
The test that catches this needs no technical knowledge whatsoever. If a service you have only ever used in a browser suddenly offers you a desktop version, go to the company's own website and check whether that version exists. Usually it does not. As the researchers put it, a download the vendor does not offer is not an upgrade, it is the attack. Tendvane's safety check looks through what is installed and running on your PC and flags remote-access tools you did not put there yourself.