Malicious GitHub repositories deploying hidden attacks on crypto wallets

Share This Post

Kaspersky researchers have identified an attack vector on GitHub that uses repositories to distribute code that targets crypto wallets.

The investigation revealed a campaign dubbed GitVenom, in which threat actors created hundreds of GitHub repositories purporting to offer utilities for social media automation, wallet management, and even gaming enhancements.

Although these repositories were designed to resemble legitimate open-source projects, their code failed to deliver the advertised functions. Instead, it embedded instructions to install cryptographic libraries, download additional payloads, and execute hidden scripts.

GitVenom repos

The malicious code appears across Python, JavaScript, C, C++, and C# projects. In Python-based repositories, a lengthy sequence of tab characters precedes commands that install packages like cryptography and fernet, ultimately decrypting and running an encrypted payload.

JavaScript projects incorporate a function that decodes a Base64-encoded script, triggering the malicious routine.

Similarly, in projects using C, C++, and C#, a concealed batch script within Visual Studio project files activates at build time. Per Kaspersky’s report, each payload is configured to fetch further components from an attacker-controlled GitHub repository.

These additional components include a Node.js stealer that collects saved credentials, digital wallet data, and browsing history before packaging the information into an archive for exfiltration via Telegram.

Open-source tools such as the AsyncRAT implant and the Quasar backdoor are also used to facilitate remote access. A clipboard hijacker that scans for crypto wallet addresses and replaces them with those controlled by the attackers is also used. 

Attack vector is not new

The campaign, which has been active for several years with some repositories originating two years ago, has triggered infection attempts worldwide. Telemetry data indicate that attempts linked to GitVenom have been most prominent in Russia, Brazil, and Turkey.

Kaspersky researchers stressed the importance of scrutinizing third-party code before execution, noting that open-source platforms, while essential to collaborative development, can also serve as conduits for malware when repositories are manipulated to mimic authentic projects.

Developers are advised to double-check the contents and activity of GitHub repositories before integrating code into their projects.

The report outlines that these projects use AI to artificially inflate commit histories and craft detailed README files. Thus, when reviewing a new repo, developers should check for overly verbose language, formulaic structure, and even leftover AI instructions or responses in these areas.

While using AI to help craft a README file is not a red flag in itself, identifying it should spur developers to investigate further before using the code. Looking for community engagement, reviews, and other projects using the repo may aid with this. However, fake AI-generated reviews and social media posts also make this a tough challenge.

The post Malicious GitHub repositories deploying hidden attacks on crypto wallets appeared first on CryptoSlate.

Read Entire Article
spot_img
- Advertisement -spot_img

Related Posts

Ethereum Foundation backs Tornado Cash developer with $1.25 million legal aid

The Ethereum Foundation has stepped in to support Alexey Pertsev, a developer behind Tornado Cash, by donating $125 million toward his legal defense Announcing the donation on Feb 26, the Foundation

Solana’s On-Chain Metrics Show Significant Decline in Network Activity, A Temporary Slowdown Or Larger Trend?

Solana has taken a hit with its price dropping toward key support levels following a sharp drop in the general crypto market SOL’s weak performance appears to have hamper investors’

Strategy (MSTR) Crashes 55%—Is A $44 Billion Bitcoin Liquidation Possible?

Shares of Strategy (NASDAQ: MSTR) have dropped by over 55% from the November 24 high at $543 to around $250 With the software intelligence firm now holding approximately 499,096 Bitcoin—worth

Lightchain AI Presale Stage 14 Nearing Completion – Don’t Miss Out

This is a paid promotional article We encourage you to conduct your own due diligence before participating in any related transactions PRESS RELEASE The crypto world is buzzing, and here’s

Is BlackRock Preparing for a Bitcoin Sell-Off with $204M Transfer?

The post Is BlackRock Preparing for a Bitcoin Sell-Off with $204M Transfer appeared first on Coinpedia Fintech News Recently, the volatility in Bitcoin’s price has increased investor anxiety, with

Top New Crypto to Buy as Binance CEO Assures Market Is in a ‘Tactical Retreat,’ Not a Reversal

Richard Teng, Binance’s CEO, firmly believes that the current crypto dump won’t last long Referencing crypto’s historical performance, Teng said that, just like traditional assets,