A malware campaign called GitVenom uses hundreds of GitHub repositories and tries to convince targets to programs information-stealing, remote access trojans (RATs), and clipboard hijackers to steal crypto and credentials.

The campaign, analyzed by Kaspersky, has been active for at least the past two years. It targets users around the world, but mainly in Russia, Brazil, and Turkey.
According to a Kaspersky researcher, the attackers behind the GitVenom campaign have created hundreds of GitHub repositories containing fake projects with malicious code. For example, there is an automation tool for interacting with Instagram accounts, a Telegram bot that allows managing Bitcoin wallets, and a hacking tool for the video game Valorant.
See also: Have I Been Pwned: 284 million accounts stolen via info-stealer malware
The researcher explains that the fake repositories are carefully crafted to appear legitimate. In addition, attackers artificially inflate the number of commits submitted to these repositories, creating a false image of high activity and further increasing credibility.
Abuse of GitHub projects to distribute malware
Analysis of repositories associated with the GitVenom campaign showed that the malicious code injected into the projects is written in various languages, such as Python, JavaScript, C, C++, and C#.
Using different languages helps avoid detection by specific tools or code review methods.
Once the victim executes the payload, the injected code downloads the second-stage program from a GitHub repository controlled by the attackers.
See also: New distribution campaigns of info-stealer malware Lumma and ACR Stealer
Kaspersky found the following tools used in the GitVenom campaign:
Node.js stealer: Infostealer malware that targets stored credentials, cryptocurrency wallet , and browsing history. It compresses the data into a .7z file and exports it via Telegram.
AsyncRAT: An open-source RAT that allows remote control, keystroke logging, screen recording, file manipulation, and command execution.
Quasar backdoor: An open-source RAT (similar to AsyncRAT).
Clipboard hijacker: Malware that monitors the victim's clipboard for cryptocurrency wallet addresses. It replaces the addresses with an address controlled by the attacker, redirecting funds to the attackers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Protection
The GitVenom malicious campaign shows that hackers have been able to effectively exploit legitimate platformslike GitHub for a long time. To protect themselves from this threat, users should thoroughly check a project before using any of its files, by inspecting the contents of the repository, scanning files with antivirus tools, and running downloaded files in an isolated environment.
See also: Phishing attacks distribute FatalRAT malware
The most common warning signs include obfuscated code, unusually automated commits, and overly detailed Readme files that appear to have been generated by AI.
Additionally, organizations should implement strict security measures to mitigate the risk posed by these types of campaigns. This includes constantly monitoring their networks for any suspicious activity, implementing strong email security , and educating employees about the risks of downloading code from unknown sources.
While public platforms like GitHub offer a convenient way for developers to collaborate and share code, they have become a target for threat actors looking to distribute malware. It is important for users, organizations, and the platforms themselves to take protective measures.
source: www.bleepingcomputer.com
