A GitHub flaw is being abused by malicious actors to distribute malware using URLs associated with Microsoft, making the files appear trustworthy.
See also: How a GitHub token exposed Mercedes-Benz source code?

While most malware activity relies on Microsoft GitHub URLs, this “flaw” could be abused with any public repository on GitHub, allowing threat actors to create very convincing lures.
Abuse of GitHub's file upload feature
Yesterday, McAfee released a report on a new LUA malware loader distributed via a legitimate Microsoft GitHub repository for the “C++ Library Manager for Windows, Linux, and MacOS,” known as vcpkg, and the STL library.
The URLs for the malware installers, shown below, clearly indicate that they belong to the Microsoft repository, but we were unable to find any reference to the files in the project's source code.
https://github[.]com/microsoft/vcpkg/files/14125503/Cheat.Lab.2.7.2.zip
https://github[.]com/microsoft/STL/files/14432565/Cheater.Pro.1.6.0.zip
The files are not part of vcpkg but were uploaded as part of a comment left on a commit or issue in the project. When leaving a comment, a GitHub user can attach a file (files, documents, etc.), which will be uploaded to the GitHub CDN and associated with the associated project using a unique URL in this format: “https://www.github. com/{project_user}/{repo_name}/files/{file_id}/{file_name}.”
For videos and images, the files will be saved in the /assets/.
See also: GitHub: Its abuse by cybercriminals is becoming more frequent
Instead of generating the URL after you post a comment, GitHub automatically generates the download link after you add the file to an unsaved comment. This allows threat actors to attach their malware to any GitHub repository without your knowledge.

Even if you decide not to publish the comment or delete it after publishing it, the files are not deleted from GitHub's CDN and the download URLs continue to work forever. Since the file URL contains the name of the repository in which the comment was created, and since almost every software company uses GitHub, this flaw could allow threat actors to promote their malware.
These URLs also appear to belong to the company's repositories, making them much more reliable.
Unfortunately, even if a company learns that its repos are being abused to distribute malware, there are no settings that allow you to manage files attached to your projects.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, you can only protect a GitHub account from malware and reputational damage by disabling comments. According to this GitHub support document, you can only temporarily disable comments for a maximum of six months at a time.
However, restricting comments can significantly impact the development of a project, as it will not allow users to report bugs or suggestions.
See also: 2023: 12 million sensitive data leaked on GitHub
GitHub is a platform that allows you to store code, track and control changes to the code, and provide tools to facilitate collaboration between developers. One of the key features of GitHub is the ability to create repositories to store and manage code. Repositories can be public or private and provide a way for developers to keep their code organized and easily accessible. GitHub uses the Git version control system, which allows developers to track and control changes to the code.
Source: bleepingcomputer
