#GitHubmalware
Fake GitHub repos are being used to spread malware.

Stay ahead of GitHub Malware.

Full guide: software.viginet.net/blog/github-...

#GitHubMalware #CyberSecurity #GitHub #Malware #InfoSec #Developer #OpenSource #TechTips
July 31, 2026 at 6:14 AM
Attackers use phony GitHub Pages and SEO poisoning to deliver Atomic infostealer to Mac users—fake repos mimic legit software, tricking users into terminal installs. Open source trust is under attack. 🖥️🎭 #MacInfostealer #GitHubMalware

buff.ly/OVV8RSw
Attackers Use Phony GitHub Pages to Deliver Mac Malware
Threat actors are using a large-scale SEO poisoning campaign and fake GitHub repositories to deliver Atomic infostealers to Mac users.
buff.ly
September 23, 2025 at 8:05 AM
French cyber spies apparently compromised EncroChat's criminal cryptophone network using off-the-shelf GitHub malware. Why write custom code when public repos exist?

#githubmalware #sameoldstory
August 17, 2026 at 6:51 AM
FakeGit Malware Campaign Abuses GitHub Repositories and AI Tools #AISecurity #FakeGitCampaign #GitHubmalware
FakeGit Malware Campaign Abuses GitHub Repositories and AI Tools
 There has been an extensive malware campaign, dubbed FakeGit, that utilizes thousands of counterfeit GitHub repositories to distribute SmartLoader malware, which is increasingly targeted at exploiting artificial intelligence (AI) tools and Model Context Protocol (MCP) servers in order to distribute the malware.  Researchers at Island have discovered that approximately 7,600 malicious GitHub repositories have been constructed by using approximately 6,600 false developers profiles, creating nearly 7,600 malicious GitHub repositories.  Thousands of repositories are masquerading as AI skills or MCP servers, offering integration with services such as Google Mail, WhatsApp, Docker, Jenkins, and Databricks. It is believed that FakeGit is an evolution of a previous malware operation that was previously associated with Water Kurita and that used Lumma Stealer.  Research by Island researchers indicates that in March 2026, the campaign began focusing on artificial intelligence-based repositories, peaking in April with hundreds of repositories impersonating artificial intelligence tools before expanding into a broader ecosystem of fake AI agents, workflows, and MCP servers. By copying code, creating convincing README files, and impersonating developer identities, the fake repositories are very closely resembling legitimate open-source projects.  A multi-stage infection chain is triggered by the download of malicious ZIP archives. Upon activation, the attack launches a LuaJIT-based loader that launches an obfuscated Lua script to install SmartLoader. SmartLoader establishes persistence on the compromised system and launches StealC, a malicious program capable of harvesting sensitive data from infected devices once it has been activated.  After installation, SmartLoader creates persistence using scheduled tasks, retrieves its C2 server using the Polygon blockchain smart contract, downloads encrypted payloads hosted on GitHub, and ultimately deploys the StealC information stealer by deploying the C2 server. A new advanced tactic, AgentBaiting, has also been identified, which highlights how AI-powered coding assistants and autonomous agents can unintentionally aid hackers in gaining control of a computer.  By optimizing fake repositories, threat actors can provide users with legitimate resources instead of forcing them to visit malicious links. Research conducted by Island researchers demonstrated that Claude Code automatically replicated malicious repositories and downloaded the associated files onto a test system, resulting in the discovery and recommendation of legitimate resources by AI models searching for free AI skills or MCP servers.  In spite of this, the AI assistant detected suspicious indicators before executing the payload, which suggests that even though AI agents can be manipulated into retrieving malicious content, they may still be capable of detecting threats later on during the execution phase. In spite of the fact that these limited tests were not intended to measure the overall detection capabilities of artificial intelligence coding assistants, Island research demonstrated that AI assistants, such as Anthropic Claude Code, Google Gemini, and OpenAI ChatGPT, could detect malicious repositories during routine searches in response to user requests.  Through artificial intelligence-assisted discovery processes, attackers can potentially pass malicious installation instructions to users without direct human interaction. More than 14 million downloads were recorded between the 335 malicious release assets hosted in approximately 211 FakeGit repositories as a result of GitHub's public statistics.  In analyzing this figure, researchers cautioned that it represents cumulative download requests, including automated activity, and should not be interpreted as a count of successful infections. According to security experts, FakeGit illustrates how trust in open-source ecosystems and AI-assisted software discovery can be exploited without directly compromising any platforms.  It is more common for attackers to distribute malware through convincing branding, fictitious developer identities, and public registries. To prevent malicious code from entering development environments, organizations should verify repository publishers, evaluate AI skills and MCP servers in isolated environments before deployment, maintain approved catalogs of trusted AI plugins, and monitor AI-assisted workflows to ensure that they are not compromised.  A number of the fake repositories were also observed to be more credible by using duplicate project descriptions, fabricating star ratings and fork counts, and impersonating legitimate developer identities, as well as impersonating legitimate developers. In this manner, malicious projects were significantly more likely to be trusted and downloaded by developers and AI-assisted coding tools.  AI agents are increasingly involved in the discovery and deployment of software, but researchers warn that the security of these automated workflows is as important as ensuring that human users are protected from traditional social engineering attacks. Using trusted developer platforms and AI-assisted workflows, cybercriminals are adjusting to the AI era through the FakeGit campaign.  The increasing reliance on AI tools and open-source repositories calls for verification of software sources, limiting untrusted AI integrations, and strengthening supply chain security.
dlvr.it
July 22, 2026 at 4:27 PM
Hidden in Plain Sight: Blockchain-Based ‘Omnistealer’ Malware Spreads via Fake Job Offers #CryptoHacking #fakejobscams #GitHubmalware
Hidden in Plain Sight: Blockchain-Based ‘Omnistealer’ Malware Spreads via Fake Job Offers
  kWhat began as a seemingly routine freelance opportunity quickly unraveled into a major cybersecurity discovery. Last year, the vice president of engineering at blockchain analytics firm Crystal Intelligence received a LinkedIn message offering web development work. Suspicious of the approach—given the rise of scams tied to fake job offers—he investigated further and uncovered something alarming. The assignment required running code hosted on GitHub. On closer inspection, the code concealed the early stages of a sophisticated cyberattack. Designed to appear harmless, it could easily deceive developers into executing it as part of routine contract work. Once activated, the code connects to blockchain networks such as TRON and Aptos, extracting data that points toward the Binance Smart Chain. From there, an additional payload is retrieved. According to Nick Smart, Crystal Intelligence’s chief intelligence officer, this final stage “fetches the final form—malicious code,” enabling extensive data theft from infected systems. Cybersecurity experts at Ransom-ISAC, a collaborative group of global researchers, have named this malware “Omnistealer.” Its capabilities are vast. “It literally steals everything,” said Ellis Stannard, a core member of the group. Their analysis revealed compatibility with over 60 cryptocurrency wallets, including MetaMask and Coinbase, as well as numerous password managers like LastPass, popular browsers such as Chrome and Firefox, and cloud platforms including Google Drive. Beyond cryptocurrency, the malware can extract sensitive credentials and access permissions. Initially resembling a typical phishing scheme, the operation turned out to be far more dangerous. By embedding malicious code in blockchain transactions—where data is permanent and difficult to remove—attackers have created a persistent and scalable threat. Researchers warn that once deployed, the malware does not distinguish between personal and corporate data, putting both individuals and organizations at risk. Investigators say the scale of the attack could surpass that of WannaCry, the global ransomware outbreak that impacted over 200,000 computers in 2017. So far, approximately 300,000 compromised credentials have been linked to this campaign, though experts believe this figure may represent only a fraction of the total. Further analysis traced parts of the operation to suspicious IP addresses, including one linked to a former U.S. consulate site in Vladivostok, Russia—previously associated with North Korean cyber activities. Smart noted the financial scale of the operation, explaining that hackers leveraging this method have accumulated millions in cryptocurrency. Researchers also discovered that elements of the malicious code had been quietly embedded in blockchain transactions years before being activated, functioning like dormant digital triggers. “Hiding malicious payloads within blockchain has become an emerging obfuscation technique,” reads a blog post written by collaborators at Ransom-ISAC. The attack primarily targets software developers and contractors. Hackers pose either as recruiters offering jobs or as freelancers seeking employment. In both cases, they exploit trust to gain access to systems or credentials. Victims have included organizations across various sectors, from financial services and defense to technology and even food delivery businesses. “Since this case, I haven't been able to look at GitHub the same way,” Stannard said, reflecting on how attackers embed malicious code into legitimate-looking repositories. Evidence increasingly points to involvement by North Korean state-backed groups. Infrastructure, malware patterns, and cryptocurrency wallets used in the campaign overlap with known operations linked to such actors. Some wallets have even been tied to previous large-scale cyber thefts. Experts suggest multiple possible motives, including financial gain, credential harvesting for identity fabrication, or enabling covert access to targeted organizations. “Everything about this has DPRK written all over it,” Stannard said, emphasizing the organized and strategic nature of the operation. The FBI has acknowledged awareness of such tactics, stating: “This technique highlights the continuing evolution of the DPRK's ability to exploit the web3 space.” Adding another layer of mystery, investigators uncovered unusual files hidden alongside the malware, including audio clips, images, and even technical documents. While their purpose remains unclear, researchers speculate these may represent experiments in covert data storage or communication. As blockchain adoption grows, experts warn that such techniques will likely become more common. The combination of low-cost execution, permanence of blockchain data, and increasingly accessible coding tools—including AI—makes these attacks easier to replicate and harder to eliminate. Authorities have been notified, but with investigations ongoing, many questions remain unanswered. For now, cybersecurity professionals urge caution—especially when dealing with unfamiliar code or unsolicited job offers, even from seemingly trusted platforms.
dlvr.it
April 25, 2026 at 8:58 AM
March 9, 2026 at 9:15 PM
December 30, 2025 at 7:00 PM
December 26, 2025 at 5:00 PM