HomeSecurityFake Microsoft Office add-ins push malware via SourceForge

Fake Microsoft Office add-ins push malware via SourceForge

Malicious users are exploiting SourceForge to distribute fake Microsoft Office add-ins, which install malware on computers , with the aim of mining and stealing cryptocurrency.

See also: Microsoft released Patch Tuesday April 2025

SourceForge malware

SourceForge.net is a legitimate software hosting and distribution platform that also supports version control, bug tracking, and dedicated forums/wikipedias, making it very popular in open source communities. Although the open source submission model offers many opportunities for misuse, malware distribution through it is rare.

The new campaign that Kaspersky has detected has affected over 4,604 systems , most of which are located in Russia. Although the malicious project is no longer available on SourceForge, Kaspersky says that the project was indexed by search engines, attracting traffic from users searching for “ Office add-ins ” or similar phrases.

The “ officepackage ” project is presented as a collection of Office Add-in development tools , with its description and files being a copy of the legitimate Microsoft project 'Office-Addin-Scripts,' which is available on GitHub .

However, when users search for office add-ins via Google (and other search engines), they receive results that lead to “officepackage.sourceforge.io,” which is hosted by a separate web hosting facility that SourceForge provides to project owners. This page mimics a legitimate developer tools page, displaying “Office Add-ins” and “Download” buttons. If either of these buttons is clicked, the victim receives a ZIP containing a password-protected file (installer.zip) and a text file with the password.

See also: Malicious OAuth applications target Microsoft 365 accounts

The archive contains a 700MB MSI file (installer.msi) , designed to evade antivirus scans . Its execution creates the files ' UnRAR.exe ' and ' 51654.rar ', and runs a Visual Basic script that downloads a batch script (confvk.bat) from GitHub.

Fake Microsoft Office add-ins push malware via SourceForge
Fake Microsoft Office add-ins push malware via SourceForge

This script checks to see if it is running in a simulated environment and which antivirus products are active, and then downloads another batch script (confvz.bat) and decompresses the RAR file.

The confvz.bat script ensures a permanent presence through registry modifications and adding Windows services.

The RAR file contains an AutoIT interpreter (Input.exe), the Netcat reverse shell tool (ShellExperienceHost.exe) , and two payloads (Icon.dll and Kape.dll).

The DLL files function as cryptocurrency miners and clippers. The former exploits the machine's computing power to mine cryptocurrency for the attacker's benefit, while the latter monitors the clipboard for copied cryptocurrency addresses and replaces them with addresses controlled by the attacker.

The attacker also obtains information from the infected system via Telegram API calls and can use the same route to inject additional malicious payloads into the compromised machine.

The malware campaign exploiting SourceForge is yet another example of how malicious actors exploit any legitimate platform to gain false legitimacy and bypass protections.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Microsoft Patch Tuesday March 2025: Fixes 57 vulnerabilities

Malware protection is very important for ensuring the security of your computer and your personal data. Here are some basic steps you can take to protect yourself from malware:

  1. Update programs and operating system
  2. Use reliable antivirus/antimalware
  3. Avoid downloading dubious files and links
  4. Use a firewall
  5. Be careful with software upgrades
  6. Evaluating app and extension permissions
  7. Use strong passwords and two-factor authentication (2FA)

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS