Infosec bytes Kaspersky says it has found more than 200 GitHub repos hosting fairly convincing-looking fake projects laced with malicious software. The Russian infosec house reckons the rotten repositories are evidence of a campaign that’s run for two years and attempts to fool developers and other netizens with projects that look authentic as they list “tens of thousands” of commits and include multi-language README.MD files. The repositories purport to offer code for Instagram aggregators, game cheats, and Telegram bots. However, they include software for stealing information and passwords, trojan malware, and code designed to hijack crypto wallets within those projects when run. Kaspersky believes the crew behind the campaign, which it’s named GitVenom, has already stolen nearly $500,000 from victims. It appears to us that at least some of the malicious repos have been taken down now. Hashes and other things to look out for to avoid falling prey to one of these infected projects are listed here. More than 20 staff at the US Digital Service – the government body renamed to form Elon Musk's cost-slashing Department of Government Efficiency, aka DOGE – have quit, citing concerns that the work they have been asked to undertake imperils security and is pointlessly destructive. The staffers reportedly sent a joint resignation letter that states: “DOGE’s actions — firing technical experts, mishandling sensitive data, and breaking critical systems — contradict their stated mission...
200-plus impressively convincing GitHub repos are serving up malware
The Register
·Iain Thomson
·Published Feb 26, 2025
·Updated
Affected Software
4 affected components
Apache BlazeDS
Adobe ColdFusion
Oracle Agile PLM=9.3.6
GitHub repositories
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the discovery of over 200 GitHub repositories that host malicious software disguised as legitimate projects.
2
What security implications are discussed?
The article highlights the risks of downloading malware from seemingly credible GitHub repositories, which can compromise user systems and data.
3
What products or software are affected?
The affected software includes Apache BlazeDS, Adobe ColdFusion, and Oracle Agile PLM.
4
Who reported the findings of the malicious GitHub repositories?
The findings were reported by Kaspersky, a cybersecurity firm.
5
What is the nature of the malicious software found in the repositories?
The malicious software is cleverly disguised to appear as legitimate projects, making it difficult for users to detect.