{"id":375670,"date":"2025-02-26T20:34:17","date_gmt":"2025-02-26T15:04:17","guid":{"rendered":"https:\/\/dripp.zone\/news\/crypto-stealing-malware-spread-through-fake-github-repositories-kaspersky-warns-crypto-news\/"},"modified":"2025-02-26T20:38:17","modified_gmt":"2025-02-26T15:08:17","slug":"crypto-stealing-malware-spread-through-fake-github-repositories-kaspersky-warns-crypto-news","status":"publish","type":"post","link":"https:\/\/dripp.zone\/news\/crypto-stealing-malware-spread-through-fake-github-repositories-kaspersky-warns-crypto-news\/","title":{"rendered":"Crypto-Stealing Malware Spread Through Fake GitHub Repositories, Kaspersky Warns &#8211; Crypto News"},"content":{"rendered":"<div style=\"position:relative;overflow:visible;font-size:1.2em;line-height:1.58\">\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Hackers are targeting software developers by spreading malware through fake GitHub repositories, according to new research.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">A lot of code on the internet is open source, meaning anyone can use it. But Kaspersky&#8217;s Securelist <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/securelist.com\/gitvenom-campaign\/115694\/\" target=\"_blank\" class=\"sc-adb616fe-0 bJsyml\">says<\/a> there&#8217;s been an uptick in cybercriminals uploading fake projects in an attempt to deceive victims.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">It warns the threat actors involved &#8220;went to great lengths to make the repositories appear legitimate to potential targets.&#8221;<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">In one case, a bogus project for a Telegram bot that manages Bitcoin wallets included malware that could allow attackers to obtain a developer&#8217;s browsing history or crypto wallet data.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Other components included a clipboard hijacker that scoured the victim\u2019s computer for wallet addresses\u2014replacing them with ones controlled by the attackers.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">As of November 2024, one such wallet had received a lump sum of about 5 BTC, worth about $443,000 at the time of writing.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Sensitive information obtained from hackers\u2014which also includes passwords and banking details\u2014is compressed and sent on to the hackers via Telegram.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Kaspersky says vigilance is needed, especially considering code-sharing platforms like GitHub are used by millions of developers around the world.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Such repositories are often used to help save time and complete projects faster by enabling builders to use code that already exists.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">&#8220;For that reason, it is crucial to handle processing of third-party code very carefully. Before attempting to run such code or integrate it into an existing project, it is paramount to thoroughly check what actions it performs,&#8221; it added.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">It&#8217;s believed that GitVenom&#8217;s impact has spread globally\u2014with most of the infections concentrated in Russia, Brazil, and Turkey.<\/p>\n<h2 class=\"sc-b2a202e4-2 bmropA gg-dark:text-white scene:font-itc-avant-garde-gothic-pro scene:font-light\" style=\"margin-top:2em;text-align:left;padding-bottom:16px;margin-bottom:16px;border-bottom:1px solid #dfe2e4\" color=\"#333\">Crypto malware targets devs<\/h2>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">This isn&#8217;t the only form of malware known to target software developers.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">Just last week, Microsoft Intelligence <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/decrypt.co\/306656\/new-malware-can-steal-crypto-on-apple-macos-devices-microsoft\" target=\"_blank\" class=\"sc-adb616fe-0 bJsyml\">warned<\/a> that a new variant of XCSSET was doing the rounds that could steal crypto on Apple macOS devices.<\/p>\n<p class=\"font-meta-serif-pro scene:font-noto-sans scene:text-base scene:md:text-lg font-normal text-lg md:text-xl md:leading-9 tracking-px text-body gg-dark:text-neutral-100\">That tends to be disseminated through infected Xcode projects, which consist of the files used to create apps for this operating system.<\/p>\n<div class=\"my-4 border-b border-decryptGridline\">\n<div class=\"text-start p-8 md:py-12 md:px-12 max-w-prose relative\"><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-[6px] md:border-l-[6px] md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute top-4 left-4 md:top-6 md:left-6\"\/><span class=\"border-t-4 border-l-4 w-4 h-4 md:border-t-[6px] md:border-l-[6px] md:w-6 md:h-6 border-decryptPurple dark:border-decryptNeon gg-dark:border-cc-pink-2 absolute rotate-180 bottom-4 right-4 md:bottom-6 md:right-6\"\/><\/p>\n<h3 class=\"font-akzidenz-grotesk font-bold text-xl md:text-3xl md:text-center gg-dark:text-white\">Daily Debrief<!-- --> Newsletter<\/h3>\n<p>Start every day with the top news stories right now, plus original features, a podcast, videos and more.<\/p>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Hackers are targeting software developers by spreading malware through fake GitHub repositories, according to new research. A lot of code on the internet is open source, meaning anyone can use it. But Kaspersky&#8217;s Securelist says there&#8217;s been an uptick in cybercriminals uploading fake projects in an attempt to deceive victims. It warns the threat actors [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":375673,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[230,225,221,227,226,228,229,60,223,224,222],"class_list":["post-375670","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency","tag-brave","tag-coinbase","tag-crypto","tag-decentralised","tag-decentralized","tag-decentralized-exchange","tag-erc-20","tag-featured","tag-meme-coin","tag-robinhood","tag-solana"],"_links":{"self":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/375670","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/comments?post=375670"}],"version-history":[{"count":1,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/375670\/revisions"}],"predecessor-version":[{"id":375674,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/posts\/375670\/revisions\/375674"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media\/375673"}],"wp:attachment":[{"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/media?parent=375670"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/categories?post=375670"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dripp.zone\/news\/wp-json\/wp\/v2\/tags?post=375670"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}