HomeSecurityGitVenom: Fake GitHub repositories distribute malware

GitVenom: Fake GitHub repositories distribute malware

A malware campaign called GitVenom uses hundreds of GitHub repositories and tries to convince targets to programs information-stealing, remote access trojans (RATs), and clipboard hijackers to steal crypto and credentials.

GitVenom Fake GitHub repositories malware

The campaign, analyzed by Kaspersky, has been active for at least the past two years. It targets users around the world, but mainly in Russia, Brazil, and Turkey.

According to a Kaspersky researcher, the attackers behind the GitVenom campaign have created hundreds of GitHub repositories containing fake projects with malicious code. For example, there is an automation tool for interacting with Instagram accounts, a Telegram bot that allows managing Bitcoin wallets, and a hacking tool for the video game Valorant.

See also: Have I Been Pwned: 284 million accounts stolen via info-stealer malware

The researcher explains that the fake repositories are carefully crafted to appear legitimate. In addition, attackers artificially inflate the number of commits submitted to these repositories, creating a false image of high activity and further increasing credibility.

Abuse of GitHub projects to distribute malware

Analysis of repositories associated with the GitVenom campaign showed that the malicious code injected into the projects is written in various languages, such as Python, JavaScript, C, C++, and C#.

Using different languages ​​helps avoid detection by specific tools or code review methods.

Once the victim executes the payload, the injected code downloads the second-stage program from a GitHub repository controlled by the attackers.

See also: New distribution campaigns of info-stealer malware Lumma and ACR Stealer

Kaspersky found the following tools used in the GitVenom campaign:

Node.js stealer: Infostealer malware that targets stored credentials, cryptocurrency wallet , and browsing history. It compresses the data into a .7z file and exports it via Telegram.

AsyncRAT: An open-source RAT that allows remote control, keystroke logging, screen recording, file manipulation, and command execution.

Quasar backdoor: An open-source RAT (similar to AsyncRAT).

Clipboard hijacker: Malware that monitors the victim's clipboard for cryptocurrency wallet addresses. It replaces the addresses with an address controlled by the attacker, redirecting funds to the attackers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

GitVenom: Fake GitHub repositories distribute malware

Protection

The GitVenom malicious campaign shows that hackers have been able to effectively exploit legitimate platformslike GitHub for a long time. To protect themselves from this threat, users should thoroughly check a project before using any of its files, by inspecting the contents of the repository, scanning files with antivirus tools, and running downloaded files in an isolated environment.

See also: Phishing attacks distribute FatalRAT malware

The most common warning signs include obfuscated code, unusually automated commits, and overly detailed Readme files that appear to have been generated by AI.

Additionally, organizations should implement strict security measures to mitigate the risk posed by these types of campaigns. This includes constantly monitoring their networks for any suspicious activity, implementing strong email security , and educating employees about the risks of downloading code from unknown sources.

While public platforms like GitHub offer a convenient way for developers to collaborate and share code, they have become a target for threat actors looking to distribute malware. It is important for users, organizations, and the platforms themselves to take protective measures.

source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS