While this repository vector is not new, researchers have uncovered a new twist for exploiting trusted metrics to hide malicious code.