Over 100,000 repositories with malicious code have been identified on GitHub.

Security researchers from Apiiro have discovered activities by attackers who are posting modified clones of repositories from various projects on GitHub, making small changes aimed at executing malicious actions. Typically, the malicious repository is created with the same name but linked to a different organization ("github.org/org1/proj" -> "github.org/org2/proj") or with a slightly altered name (typosquatting), with the expectation that the victim will not notice the differences and will use the code with malicious modifications. To attract users, links to the malicious repositories are actively posted on various social networks, forums, and chats.

Reports indicate the identification of more than 100,000 such repositories, but researchers suggest that the total number of posted repositories with malicious changes may reach millions, as the overwhelming majority of automatically created repositories are deleted by GitHub within a few hours of their posting. Among the masks that can be used to identify the existence of malicious inserts in uploaded repositories are mentioned: exec(Fernet exec(requests exec(__import exec(bytes exec(“””\nimport exec(compile __import__(“builtins”).exec(,

The attached malicious code is a modified version of BlackCap-Grabber, which, upon execution, searches for sensitive data such as account credentials, tokens, saved browser passwords, and Cookies, and sends them to server the attackers. The malicious code also supports the hijacking of cryptocurrency addresses transmitted via the clipboard, can take screenshots, and receive commands from the command center server (C&C)

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster