Researchers at the Leiden Institute of Advanced Computer Science found thousands of repositories on GitHub that offer fake proof-of-concept (PoC) exploits for various vulnerabilities and include malware.
Researchers commonly use GitHub to publish PoC exploits and help the cybersecurity verify fixes for vulnerabilities or determine the impact and scope of a vulnerability.

Researchers at the Leiden Institute of Advanced Computer Science claim that the probability of someone becoming infected with malicious software instead of obtaining real PoC exploits on GitHub could reach 10.3%, excluding proven fakes and prankware.
See also: Consumers: IoT vehicles must be properly protected from cyber threats
The researchers analyzed more than 47,300 repositories on GitHub advertising an exploit for a vulnerability disclosed between 2017 and 2021. They used three mechanisms for the analysis:
- IP address analysis: comparing the PoC publisher's IP with public blocklists and VT and AbuseIPDB.
- Binary Analysis: performing VirusTotal checks on the provided executables and their hashes.
- Hexadecimal and Base64 analysis: decoding obfuscated files before performing binary and IP checks.
Out of the 150,734 unique IP addresses extracted, 2,864 matched entries in the blocklists, 1,522 were identified as malicious in virus protection scans on Virus Total and 1,069 of them were present in the AbuseIPDB database.
The binary analysis examined a set of 6.160 executables and revealed a total of 2.164 malicious samples that were hosted in 1.398 GitHub repositories.
See also: New version of Ursnif malware – known as Gozi – released
According to the researchers, 4,893 repositories out of 47,313 examined were deemed malicious, with most of them involving vulnerabilities from 2020.
The report contains a small set of repositories with fake PoCs that delivered malware. However, the researchers shared with BleepingComputer at least 60 other examples that are still available and in the process of being removed from GitHub.

GitHub: Fake PoC exploits with malware
Researchers found a plethora of different malware and malicious scripts, ranging from remote access trojans to Cobalt Strike.
An interesting case is that of a PoC for the CVE-2019-0708 vulnerability , also known as “BlueKeep”, which contains a base64-obfuscated Python script that retrieves a VBScript from Pastebin. The script is the Houdini RAT , an old JavaScript-based trojan that supports remote command execution via Windows CMD .
Researchers also identified another case where a fake PoC was actually information-stealing malware.
See also: OldGremlin: Uses Linux ransomware to target Russian organizations
One of the researchers, El Yadmani Soufian, who is also a security researcher at Darktrace, told BleepingComputer other examples of malware inside fake exploits on GitHub, which are not included in the white paper.
For example:
- PowerShell PoC that contains a binary encoded in base64 that has been flagged as malicious on Virus Total.
- Python PoC that contains a one-liner that decodes a base64-encoded payload that has been flagged as malicious on Virus Total.
- Fake BlueKeep exploit containing an executable file that is flagged by most antivirus engines as malicious.
Protection measures
GitHub is one of the most popular code, however, we should not completely trust a repository located on the platform, especially when it comes from an unverified source.
Software testers should carefully review the PoCs they download and perform as many checks as possible before executing them.
Researcher Soufian recommends to the testers to do the following:
- Carefully read the code you are going to run on network or your customer's network.
- If the code is highly obfuscated and takes a long time to analyze manually, place it in a sandbox (e.g. isolated virtual machine) and monitor your network for any suspicious traffic.
- Use open-source intelligence tools like VirusTotal to analyze binaries.
All malicious repositories discovered on GitHub have been reported, but it will take some time before they are examined and all are removed.
Source: www.bleepingcomputer.com
