Tech

Hundreds of GitHub repositories hijacked to trick users into downloading malware

Share
Share


  • Kaspersky research finds “hundreds” of malicious GitHub commits
  • Commits pretend to be useful software but trick victims into downloading malware
  • At least one person lost 5 BTC because of the campaign

Cybersecurity researchers Kaspersky have iscovered a longstanding, widespread criminal campaign targeting software developers with information-stealing malware.

Kaspersky said it observed hundreds of fake GitHub repositories, some posing as tools and automation mechanisms, others as hacks and cracks, that were actually delivering different sorts of malware to their victims. They dubbed the campaign ‘GitVenom’. Apparently, someone has been very thorough, carefully setting up commits, writing accompanying documentation and readme files, all in order to avoid being flagged as malware.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles
New method quickly assesses underwater landslide risk for offshore turbines
Tech

New method quickly assesses underwater landslide risk for offshore turbines

Illustration of dynamic forces acting on monopile and tower, and soil-structure interaction....

Chuwi’s CoreBook X gets spec bump but lacks graphical muscle
Tech

Chuwi’s CoreBook X gets spec bump but lacks graphical muscle

Chuwi’s new CoreBook X features Intel i9-13900HK and 32GB RAM No discrete...

UK Prices for LG’s 2025 QNED TVs are live, and Samsung should be worried
Tech

UK Prices for LG’s 2025 QNED TVs are live, and Samsung should be worried

LG has revealed pricing for its 2025 QNED TV range The lineup...