GitHub faces widespread malware attacks affecting projects, including crypto

GitHub faces widespread malware attacks affecting projects, including crypto


Major developer platform GitHub faced a widespread malware attack and reported 35,000 “code hits” on a day that saw thousands of Solana-based wallets drained for millions of dollars.

The widespread attack was highlighted by GitHub developer Stephen Lucy, who first reported the incident earlier on Wednesday. The developer came across the issue while reviewing a project he found on a Google search.

So far, various projects — from crypto, Golang, Python, JavaScript, Bash, Docker and Kubernetes — have been found to be affected by the attack. The malware attack is targeted at the docker images, install docs and NPM script, which is a convenient way to bundle common shell commands for a project.

To dupe developers and access critical data, the attacker first creates a fake repository (a repository contains all of the project’s files and each file’s revision history) and pushes clones of legit projects to GitHub. For example, the following two snapshots show this legit crypto miner project and its clone.

okex
Original crypto mining project. Source: Github
Cloned crypto mining project. Source: Github

Many of these clone repositories were pushed as “pull requests,” which let developers tell others about changes they have pushed to a branch in a repository on GitHub.

Related: Nomad reportedly ignored security vulnerability that led to $190M exploit

Once the developer falls prey to the malware attack, the entire environment variable (ENV) of the script, application or laptop (Electron apps) is sent to the attacker’s server. The ENV includes security keys, Amazon Web Services access keys, crypto keys and much more.

The developer has reported the issue to GitHub and advised developers to GPG-sign their revisions made to the repository. GPG keys add an extra layer of security to GitHub accounts and software projects by providing a way of verifying all revisions come from a trusted source.





Source link

Leave a Reply

Your email address will not be published. Required fields are marked *

You have not selected any currency to display

Pin It on Pinterest

Ico-Investor
Coinmama
Ico-Investor
GitHub faces widespread malware attacks affecting projects, including crypto
okex
Changelly
Bitcoin Price Prediction 2025
top loser
CZ Calls for Dark Pool Perp DEX to Shield Traders from Front-Running in DeFi
Unilabs
96% of NFTs Deemed 'Dead' as Market Struggles with Speculation and Volatility
XTZ Price Analysis: As Bulls Target $2.27, Is $18 a Realistic Target?
Paxful
TokenMetrics
Ethereum Foundation rolls out new treasury policy
Price predictions for BTC, ETH, XRP, BNB, SOL, DOGE, ADA, SUI, HYPE, LINK
Blackrock’s Tokenized Money Market Fund BUIDL Tops $10M in May Dividends
Circle Raises $1.1 Billion in Upsized IPO, Prices Shares at $31
10 Best Meme Coins to Watch in June 2025
Ethereum Foundation rolls out new treasury policy
Price predictions for BTC, ETH, XRP, BNB, SOL, DOGE, ADA, SUI, HYPE, LINK
Blackrock’s Tokenized Money Market Fund BUIDL Tops $10M in May Dividends
Circle Raises $1.1 Billion in Upsized IPO, Prices Shares at $31