Kaspersky warns of malware-ridden GitHub projects: how hackers are stealing credentials

February 26, 2025 02:59 AM PST | By Invezz
 Kaspersky warns of malware-ridden GitHub projects: how hackers are stealing credentials
Image source: Invezz

Cybercriminals are exploiting GitHub to spread credential-stealing malware through fake repositories, cybersecurity firm Kaspersky has warned.

The campaign, dubbed “GitVenom,” involves attackers creating seemingly legitimate projects filled with malicious code that infects users’ devices upon download.

These repositories are designed to target developers, crypto users, and businesses relying on open-source software.

Kaspersky’s research, published on February 24, highlights how threat actors manipulate GitHub’s platform to make their repositories appear credible.

By leveraging artificial intelligence to generate documentation and updating timestamps to suggest active development, hackers trick unsuspecting users into downloading and executing malware.

The risks extend beyond developers looking for open-source tools.

The malware in these repositories includes info-stealers, remote access trojans (RATs), and clipboard hijackers, all aimed at siphoning credentials, cryptocurrency wallets, and personal data.

With cybercriminals continuously refining their tactics, GitHub users are facing an evolving cybersecurity threat that extends across multiple industries.

Malware disguised as software

Kaspersky’s report details how hackers are using deceptive tactics to push malware under the guise of helpful tools.

Many fake repositories claim to offer software such as Telegram bots for managing Bitcoin wallets or automation tools for social media platforms like Instagram.

In reality, these projects serve as a front for distributing malware designed to harvest sensitive data.

Once installed, the malware activates and begins extracting login credentials, cryptocurrency wallet information, and browsing history.

The stolen data is then transmitted to attackers via Telegram, allowing them to access accounts and steal funds remotely.

Clipboard hijackers further increase the risk by monitoring copied wallet addresses and replacing them with hacker-controlled addresses—redirecting transactions to cybercriminals.

Kaspersky’s research found that many of these malicious projects have been active for at least two years, highlighting their effectiveness in deceiving victims.

The sophistication of these attacks suggests that cybercriminals have identified GitHub as a lucrative vector for distributing malware, and they are likely to continue refining their techniques.

Crypto thefts linked to GitVenom

The impact of the GitVenom campaign has been significant, with hackers successfully siphoning funds from unsuspecting victims.

In one instance reported in November 2024, a hacker-controlled wallet received five Bitcoin, valued at approximately $442,000 at the time.

While the malware-ridden GitHub repositories have been discovered worldwide, Kaspersky notes that users in Russia, Brazil, and Turkey have been disproportionately affected.

Given the vast number of developers and businesses relying on GitHub for software development, these attacks could escalate if proactive security measures are not adopted.

The increasing use of AI-generated documentation and deceptive update logs suggests that threat actors are evolving their methods to avoid detection.

Security researchers warn that unless GitHub and its users implement stricter vetting processes, similar malware campaigns will persist, leading to more credential thefts and financial losses.

Crypto industry lost $1.49B in 2024

Kaspersky’s findings align with broader cybersecurity trends in the crypto space.

According to a report from blockchain security firm Immunefi, the crypto industry suffered $1.49 billion in losses due to hacks and fraud in 2024.

This marked a 17% decline from 2023, yet hacking incidents remained the primary cause of financial losses.

Of the total $1.49 billion lost, $1.47 billion—98.1%—was attributed to hacks, with 192 documented incidents.

Fraud, including rug pulls and exit scams, accounted for $28 million, representing only 1.9% of the total losses.

However, fraud cases surged by 72% year-on-year, reflecting a growing sophistication in cybercriminal tactics.

While the decline in overall losses suggests improved security measures, the number of attacks remains high.

In 2023, 320 hacking incidents were reported, compared to 232 in 2024—a 27.5% reduction.

Cybersecurity experts warn that despite the progress, platforms like GitHub continue to be exploited, and more targeted security strategies are necessary to mitigate risks.

As cybercriminals refine their approaches, organisations and developers must exercise caution when downloading software from open-source platforms.

The rise of AI-generated fake repositories, coupled with the ongoing threat of crypto-related cyberattacks, underscores the need for enhanced verification methods to prevent large-scale financial losses.

The post Kaspersky warns of malware-ridden GitHub projects: how hackers are stealing credentials appeared first on Invezz


Disclaimer

The content, including but not limited to any articles, news, quotes, information, data, text, reports, ratings, opinions, images, photos, graphics, graphs, charts, animations, and video (Content) is a service of Kalkine Media LLC., having Delaware File No. 4697309 (“Kalkine Media, we or us”) and is available for personal and non-commercial use only. The principal purpose of the Content is to educate and inform. The Content does not contain or imply any recommendation or opinion intended to influence your financial decisions and must not be relied upon by you as such. Some of the Content on this website may be sponsored/non-sponsored, as applicable, but is NOT a solicitation or recommendation to buy, sell or hold the stocks of the company(s) or engage in any investment activity under discussion. Kalkine Media is neither licensed nor qualified to provide investment advice through this platform. Users should make their own enquiries about any investments and Kalkine Media strongly suggests the users to seek advice from a financial adviser, stockbroker or other professional (including taxation and legal advice), as necessary. Kalkine Media hereby disclaims any and all the liabilities to any user for any direct, indirect, implied, punitive, special, incidental or other consequential damages arising from any use of the Content on this website, which is provided without warranties. The views expressed in the Content by the guests, if any, are their own and do not necessarily represent the views or opinions of Kalkine Media.
The content published on Kalkine Media also includes feeds sourced from third-party providers. Kalkine does not assert any ownership rights over the content provided by these third-party sources. The inclusion of such feeds on the Website is for informational purposes only. Kalkine does not guarantee the accuracy, completeness, or reliability of the content obtained from third-party feeds. Furthermore, Kalkine Media shall not be held liable for any errors, omissions, or inaccuracies in the content obtained from third-party feeds, nor for any damages or losses arising from the use of such content. Some of the images/music that may be used on this website are copyrighted to their respective owner(s). Kalkine Media does not claim ownership of any of the pictures/music displayed/used on this website unless stated otherwise. The images/music that may be used on this website are taken from various sources on the internet, including paid subscriptions or are believed to be in public domain. We have used reasonable efforts to accredit the source (public domain/CC0 status) to where it was found and indicated it, as necessary.
This disclaimer is subject to change without notice. Users are advised to review this disclaimer periodically for any updates or modifications.


Sponsored Articles


Investing Ideas

Previous Next