A fake PoC for a Linux kernel vulnerability on GitHub exposed researchers to malware.

In a sign that cybersecurity researchers continue to fall under the radar of malicious actors, a proof-of-concept (PoC) has been discovered on GitHub, which contains a backdoor with a “sly” persistence method.
The repository was disguised as a proof-of-concept (PoC) for CVE-2023-35829, a recently disclosed high-severity flaw in the Linux kernel. It has since been taken down, but not before being forked (developers take a copy of the source code from a software package and begin independent development of it) 25 times. Another PoC shared by the same account, ChriSanders22, for CVE-2023-20871, a privilege escalation bug affecting VMware Fusion, was taken down twice.
Uptypcs also spotted a second GitHub profile containing a fake PoC for CVE-2023-35829. It is still available at the time of writing and has been forked 19 times. A closer look at the commit history shows that the changes were pushed by ChriSanders22, suggesting that it was forked from the original repository.

The backdoor has a wide range of capabilities to steal sensitive data from compromised hosts as well as allow a threat actor to gain remote access by adding their SSH key to the .ssh/authorized_keys file.
The development came nearly a month after VulnCheck discovered multiple fake GitHub accounts masquerading as security researchers and intending to distribute malware under the guise of PoC exploits for popular software like Discord, Google Chrome, Microsoft Exchange Server, Signal , and WhatsApp.
It is recommended that users who have downloaded and run the PoCs unauthorize their SSH keys, delete the kworker file, remove the kworker path from the bashrc file, and check /tmp/.iCE-unix.pid for potential threats.
Information source: thehackernews.com
