HomeSecurityMalicious Visual Studio projects on GitHub push Keyzetsu

Malicious Visual Studio projects on GitHub push Keyzetsu

Malicious actors are abusing GitHub's automation capabilities and malicious Visual Studio to push a new variant of malware that exploits the “Keyzetsu” clipboard and steals cryptocurrencies.

See also: How a GitHub token exposed Mercedes-Benz source code?

GitHub Keyzetsu

Attackers create GitHub repositories with names that are more likely to rank high in search results and use various methods to artificially boost their popularity and visibility on the platform.

Users who download files from these repositories are infected with malware that hides within Visual Studio project files and is secretly executed during the project build.

According to a new report by Checkmarx, the Keyzetsu malware campaign uses multiple GitHub repositories named after popular topics and projects.

The attackers used GitHub Actions to automatically update these repositories at a very high frequency, modifying a log file with a small random change. This is done so that the repos rank high in search results categorized as “most recently updated.”

See also: GitHub: Its abuse by cybercriminals is becoming more frequent

Another potentially automated process is the creation of fake GitHub accounts that add fake stars to these repositories to create a false sense of popularity and credibility around the project. One example is that all of these accounts were recently created.

Malicious Visual Studio projects on GitHub push Keyzetsu

The Keyzetsu malware payload is typically hidden within build events in malicious Visual Studio GitHub project files, although Checkmarx has seen some variations.

To protect against attacks and malicious code hosted on GitHub, check repository activity for suspicious patterns, such as multiple commits or stars received from accounts created at the same time.

See also: 2023: 12 million sensitive data leaked on GitHub

What are the methods of protection against malware?

The first and most important method of protection against malware, such as Keyzetsu on GitHub, is to use reliable security software. This software should include anti-spyware and anti-malware features. In addition, it is important to keep your operating system and all applications up to date. These updates often include security patches that can protect computer from the latest threats. You should also be careful with the emails and messages you receive. Using strong passwords and changing them regularly is another important method of protection. Finally, using a virtual private network (VPN) can help protect your data from monitoring and misuse.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS