HomeSecurityNew Gitloker attacks delete GitHub repos

New Gitloker attacks delete GitHub repos

Malicious actors are targeting GitHub repositories with Gitloker attacks, deleting their content, and asking victims to contact them via Telegram for more information.

See also: GitHub warns of SAML auth bypass flaw

Gitloker GitHub

These attacks are part of what appears to be an ongoing campaign that was first spotted on Wednesday by Germán Fernández, a security researcher at Chilean cybersecurity firm CronUp.

The threat actor behind this campaign – who runs Gitloker on Telegram and poses as a cyber incident analyst – is likely hacking targets’ GitHub accounts using stolen credentials.

They then claim to steal victims' data, creating a backup that could help restore deleted data. They then rename the repository and add a single README.me, instructing victims to contact Telegram.

“I hope this message finds you well. This is an urgent notification to inform you that your data has been compromised and we have secured a backup,” the ransom notes state.

See also: GitHub comments are being abused to promote malware

Following previous attacks on GitHub users, the company advised users to change their passwords to protect their accounts from Gitloker attacks. This should protect against malicious actions such as adding new SSH keys, authorizing new applications, or modifying team members.

New Gitloker attacks delete GitHub repos

To prevent attackers from compromising your GitHub account and detect any suspicious activity, you should also:

  • Enable two-factor authentication.
  • Add a password for secure, passwordless login.
  • Review and revoke unauthorized access to SSH keys, deployment keys, and authorized integrations.
  • Verify all email addresses associated with your account.
  • Check the account security logs to monitor changes in the storage space.
  • Manage webhooks in repositories .
  • Check and revoke any new development keys.
  • Regularly check recent commits and collaborators for each repository.

See also: Malicious Visual Studio projects on GitHub push Keyzetsu

GitHub, which has been the target of Gitloker attacks, is an online platform that uses Git, a version control system, to facilitate collaborative software development. It hosts code repositories that developers can clone, modify, and merge, enabling efficient project management and seamless collaboration. In addition to storing code, GitHub offers issue tracking, project wikis, and continuous integration services, making it a complete tool for developers. The platform also supports extensive community engagement, allowing developers to contribute to open source projects, share knowledge, and showcase their work through detailed documentation and README.

Source: bleepingcomputer

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS