Friday, September 11, 2026

200 Malicious GitHub Repositories Distributing Malware to Developers

A sophisticated malware campaign dubbed GitVenom has infected over 200 GitHub repositories, targeting developers with fake projects masquerading as legitimate tools.

The repositories, active for nearly two years, deploy stealers, remote access Trojans (RATs), and clippers to compromise systems and steal sensitive data, including cryptocurrency wallets.

According to the Kaspersky Report, Security researchers estimate the threat actors behind GitVenom have stolen at least 5 BTC (≈$485,000) through this operation.

Campaign Mechanics and Evasion Tactics

The malicious repositories impersonate popular developer tools, including Telegram bots, Valorant hacking utilities, Instagram automation scripts, and Bitcoin wallet managers.

To evade detection, attackers meticulously craft README.MD files in multiple languages, complete with installation guides, usage examples, and troubleshooting tips.

For example, a Python-based “Instagram follower bot” repository included step-by-step instructions for configuring API keys—a tactic meant to build trust before deploying malware.

Attackers used AI to write detailed instructions in multiple languages

Automated Commit Spoofing

Attackers automated repository activity by generating timestamp-based commits every few minutes, creating the illusion of active maintenance.

One repository logged over 12,000 commits in six months, mimicking the update patterns of legitimate open-source projects.

This strategy helped malicious repositories evade GitHub’s default “sorted by recently updated” filters, pushing them higher in search results.

Malware Payloads and Financial Impact

GitVenom’s repositories span Python, JavaScript, C, C++, and C#, broadening their attack surface. Malicious payloads include:

  • Node.js Stealer: Harvests usernames, passwords, browser history, and cryptocurrency wallet data, compresses it into a .7z archive, and exfiltrates it via Telegram bots.
  • AsyncRAT: An open-source RAT enabling keylogging, screen capture, and remote command execution.
  • Clipper Malware: Scans clipboards for cryptocurrency addresses and substitutes them with attacker-controlled wallets. In November 2024, one wallet linked to this campaign received a single 5 BTC transfer.

Victims span Russia, Brazil, Turkey, and Southeast Asia, with lures tailored to regional developer interests.

Brazilian repositories promoted “CPF generators” (national ID tools), while Turkish repos advertised VPN bypass tools for streaming platforms.

Experts recommend manually reviewing code dependencies before integration, particularly for projects lacking two-factor authentication (2FA) among contributors.

Attackers frequently used single-contributor accounts created days before repository publication.

  • Audit Stars and Forks: Legitimate projects typically accrue organic engagement over time. A repository with 200 stars but only two forks may indicate bot activity.
  • Monitor Direct Links: Avoid downloading repositories shared via unsolicited messages or unverified forums. Attackers often use URL shorteners to mask GitHub links.

The GitVenom campaign underscores the escalating risks of supply chain attacks in open-source ecosystems.

As threat actors refine their social engineering tactics, developers must adopt defensive practices—from rigorous code audits to endpoint protection tools.

GitHub has removed the identified repositories, but researchers warn copycat campaigns are inevitable.

Vigilance remains the cornerstone of cybersecurity in an era where malicious innovation outpaces traditional defenses.

Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response, and Threat Hunting - Register Here

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News