The malicious Stargazer Goblin gang has created a network of fake GitHub to create a Distribution-as-a-Service (DaaS) that distributes malware, which steals information and resulted in $100,000 in illegal profits last year.

The network, which includes over 3,000 accounts on the cloud-based code hosting platform, spans thousands of repositories used to share malicious links and software. This network has been labeled by Check Point as the “Stargazers Ghost Network.”.
Read also: Over 3,000 GitHub accounts used to distribute malware
Some of the malware families spread using this method include Atlantida Stealer, Rhadamanthys, RisePro, Lumma Stealer, and RedLine, with the fake accounts also engaging in prototyping, forking, tracking, and subscribing to malicious repositories to give them an appearance of legitimacy.
The network is believed to have been active since August 2022 in some preliminary form, although an advertisement for DaaS was not spotted in the dark until early July 2023.
“Hackers have created a network of “Ghost” accounts, which distribute malware via dangerous links to their repositories and encrypted files as releases,” security researcher Antonis Terefos explained in an analysis published last week.
“This network not only distributes malware, but also provides various other activities that make these “Ghost” accounts appear as regular users, lending false legitimacy to their actions and related repositories.”
Different categories of GitHub accounts are responsible for different aspects of the system in an effort to make their infrastructure more resilient to removal attempts by GitHub when malicious payloads are flagged on the platform.
These include accounts that serve the phishing repository template, accounts that provide the image for the phishing template, and accounts that promote malware in repositories in the form of a password-protected file disguised as cracked software and game cheats.
If the third set of accounts is detected and blocked from GitHub, Stargazer Goblin proceeds to update the first account's phishing repository with a new link to a new active malicious version, thus allowing the operators to proceed with minimal disruption.
In addition to wanting new releases from multiple repositories and committing changes to README.md files to modify download links, there is evidence to suggest that some accounts part of the network have previously been compromised, with credentials likely obtained through credential theft malware.
"Most of the time, we observe that Repository and Stargazer accounts remain unaffected by repository bans and removals, while Commit and Release accounts are usually banned once their malicious repositories are detected," said Terefos.
“It is common to find link repositories that contain links to banned release repositories. When this happens, the Commit account associated with the Link Repository updates the malicious link with a new one.”
One of the campaigns discovered by Check Point involves the use of a malicious link to a GitHub repository that, in turn, leads to a PHP script hosted on a WordPress site and delivers an HTML application (HTA) file to ultimately execute the Atlantida Stealer through a PowerShell script.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See more: Grand Theft Auto VI – Fake beta version spreads malware
Other malware families spread via DaaS include Lumma Stealer, RedLine Stealer, Rhadamanthys, and RisePro. Check Point further noted that the GitHub accounts are part of a larger DaaS solution that operates similar ghost accounts on other platforms such as Discord, Facebook, Instagram, X, and YouTube.
“Stargazer Goblin has created a highly sophisticated malware distribution mechanism that evades detection by pretending GitHub is a legitimate website, bypasses suspicions of malicious activity, and minimizes and recovers any damage when GitHub disrupts its network,” Terefos said.
"The use of multiple accounts and profiles that perform different activities from stargazing to hosting the repository, phishing template binding, and hosting malicious releases, allows the Stargazers Ghost Network to minimize its losses when GitHub takes action to disrupt its operations, as typically only a portion of the entire operation is disrupted instead of all of the accounts involved.".
The development comes as unknown threat actors are targeting GitHub repositories, wiping out their content, and asking victims to contact a user named Gitloker on Telegram as part of a new extortion operation that has been ongoing since February 2024.
The social engineering targets developers with phishing emails sent from “notifications@github.com,” aiming to trick them into clicking fake links under the guise of a GitHub job opportunity, after which they are asked to authorize a new OAuth application that deletes all repositories and demands payment in exchange for restoring access.
It also follows an advisory from Truffle Security that sensitive data can be accessed from deleted forks, deleted repositories, and even private repositories on GitHub, urging organizations to take steps to protect themselves from what it calls a Cross Fork Object Reference (CFOR) vulnerability.
“A CFOR vulnerability occurs when a repository fork can access sensitive data from another fork (including data from private and deleted forks),” said Joe Leon. “Similar to an insecure direct object reference, CFOR provides users with commit hashes to directly access commit data that would otherwise not be visible to them.”
In other words, a piece of code committed to a public repository can be accessible forever as long as there is at least one fork of that repository. Furthermore, it could also be used to access code committed from the time an internal fork is created until the repository is made public.

It's worth noting that these design decisions are intentional and come from GitHub, as stated in its official documentation.
When you convert a private repository to public, all commits associated with that repository, including any commits that were made in repositories from which it was forked, will become visible to everyone.
Read more: APT41 hacking gang uses StealthVector malware
"The average user sees the separation of private and public repositories as a security boundary and reasonably believes that any data located in a private repository cannot be accessed by public users," Leon said.
Unfortunately, this is not always the case. Furthermore, the deletion process involves data loss. As we mentioned earlier, deleting a repository or fork does not mean that your data is actually deleted.
Source: thehackernews
