HomeSecurityGitHub: Warns Java developers about new malware

GitHub: Warns Java developers about new malware

GitHub

GitHub Inc. is warning developers about a new malware thatis spreading on its site through boobytrapped Java projects.

The malware, which the GitHub security team has dubbed Octopus Scanner, was found in projects managed by developers using the Apache NetBeans IDE (integrated development environment), a tool for Java applications .

GitHub said that following a tip from a security researcher, it found 26 repositories uploaded to site that contained the malware .

If a user downloads any of these 26 projects, the malware will spread to local systems and infect them.

It will scan the victim's workstation for a local installation of NetBeans IDE and proceed to other Java projects of the developer.

developers

The goal is to install a Remote Access Trojan (RAT)

The malware can run on Windows, macOS, and Linux. The final step of the infection is the installation of a remote access trojan (RAT), which allows the operator of Octopus Scanner to infiltrate the computer , searching for sensitive information.

GitHub says the Octopus Scanner campaign is not new. The oldest sample of the malware was uploaded to VirusTotal in August 2018.

GitHub says it found only 26 projects on its site with traces of Octopus Scanner, but believes many more projects have been infected over the past two years.

However, the real purpose of the attack was to place a RAT on the machines of developers working on sensitive projects or at large companies software , and not necessarily to infect open-source Java projects.

The RAT can give the attacker access to steal confidential information about upcoming tools, source code, etc.

"It was interesting that this malware attacked the NetBeans build process especially because it is not the most common Java IDE in use today," said the GitHub security team.

"If the malware developers took the time to implement this malware specifically for NetBeans, it means it could either be a targeted attack or they have already implemented the malware for systems like Make, MsBuild, Gradle, and others," GitHub added.

GitHub did not publish the names of the 26 poisoned projects, but did publish details about the infection process followed by Octopus Scanner.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS