Another tactic I have seen is these hackers would message people on other social media websites (Discord being a common one which I have seen this on) saying that they have just made a game they would like you to play and give feedback on, sometimes these Discord accounts are hacked accounts, sometimes it will be a friend of someone they have hacked which will ask them to play their game which helps the fake game look more legitimate and more trustworthy to download.
I believe the malware with this tactic typically targets Discord accounts instead of Itch accounts, although it could indeed target a lot more, either way it is another tactic to watch out for.
The thread below actually gives a lot more detail on this scam:
https://itch.io/t/1659440/psa-beware-the-try-my-game-scam