Malicious GitHub repositories deploying hidden attacks on crypto wallets

Malicious GitHub repositories deploying hidden attacks on crypto wallets

Kaspersky researchers have identified an attack vector on GitHub that uses repositories to distribute code that targets crypto wallets.
The investigation revealed a campaign dubbed GitVenom, in which threat actors created hundreds of GitHub repositories purporting to offer utilities for social media automation, wallet management, and even gaming enhancements.
Although these repositories were designed to resemble legitimate open-source projects, their code failed to deliver the advertised functions. Instead, it embedded instructions to install cryptographic libraries, download additional payloads, and execute hidden scripts.
GitVenom repos
The malicious code appears across Python, JavaScript, C, C++, and C# projects. In Python-based repositories, a lengthy sequence of tab characters precedes commands that install packages like cryptography and fernet, ultimately decrypting and running an encrypted payload.
JavaScript projects incorporate a function that decodes a Base64-encoded script

Czytaj więcej

We współpracy z: https://cryptoslate.com/kaspersky-discovers-github-repo-poisoning-used-to-steal-bitcoin/

Total
0
Shares
Dodaj komentarz

Podobne Wpisy