Just in:
Leaderless Student Protests Pose New Challenge To National Politics // Messi returns as Inter Miami bow out // Bora Group Posts Record 2Q26 Revenue and Strong Profits as Margins expand and Operations Resume Demand-Driven Growth // DP World sets $3 billion global expansion drive // ExfilSquad data leaks substantiate broad breach claims // UAE condemns Iran over attacks on ADNOC vessels // Cambodia Government and Church Leaders Celebrate Opening of Phnom Penh Temple // Sukuk liquidity outpaces Gulf bonds as markets recover // Dubai shares retreat as earnings deepen market caution // Russia sends second homebuilt LNG carrier into Arctic // XTransfer Serves Over 1 Million Enterprise Clients // Indonesia quake kills at least 20 on Flores // NINGJI Takes Centre Stage at KLCC, Strengthening Its Position as a Benchmark for Southeast Asian Expansion Through Five Key Localization Strategies // “YOU BRING CHARM TO THE WORLD — The 18th Global Chinese Awards” Concludes in Beijing // NINGJI Takes Centre Stage at KLCC, Strengthening Its Position as a Benchmark for Southeast Asian Expansion Through Five Key Localization Strategies // Etiqa Insurance Singapore Appoints Claudia Soh as Chief Executive Officer to Lead Next Chapter of Growth // Biotechnology and AI Reshape Medicine Development Across the UAE and Beyond // Minimal Phone 2 shifts focus with AMOLED upgrade // FBI and NCAA step up athlete cyber protection // PayerMax Enables Last War to Integrate Rakuten Pay, Expanding Market Access to Japan //

Cybercriminals Exploit Fake GitHub Projects to Steal Bitcoin

github crypto thefts fake id

Cybercriminals are leveraging counterfeit GitHub repositories to distribute malware, resulting in the theft of approximately $485,000 in Bitcoin, according to cybersecurity firm Kaspersky. The malicious campaign, dubbed “GitVenom,” has been active for at least two years and primarily targets developers and cryptocurrency enthusiasts.

Kaspersky’s Global Research and Analysis Team identified over 200 deceptive repositories on GitHub. These repositories masquerade as legitimate projects, such as automation tools for Instagram, Telegram bots for managing Bitcoin wallets, and software for popular games like Valorant. However, instead of providing the advertised functionalities, these projects are embedded with multistage malware designed to steal personal and financial data.

The GitVenom campaign employs a variety of programming languages, including Python, JavaScript, C, C++, and C#. The malicious code is strategically placed within the projects, often concealed within seemingly benign files. Once executed, the malware can hijack clipboard contents to replace cryptocurrency wallet addresses, enabling the redirection of funds to the attackers’ wallets. Additionally, it can exfiltrate sensitive information, such as login credentials and personal data, from the victim’s system.

One notable incident involved a developer who downloaded a purported Telegram bot from GitHub to manage Bitcoin transactions. Unbeknownst to the developer, the bot contained malicious code that intercepted and altered wallet addresses during transactions. This led to the loss of over 5 Bitcoins, equivalent to approximately $485,000 at the time of the theft.

The geographical distribution of the attacks indicates a global reach, with the highest number of incidents reported in Brazil, Turkey, and Russia. The widespread nature of the campaign underscores the importance of vigilance among developers and cryptocurrency users worldwide.

Kaspersky’s analysis reveals that the threat actors behind GitVenom meticulously craft their repositories to appear authentic. They include detailed README.md files, comprehensive documentation, and even AI-generated activity logs to enhance credibility. This level of sophistication makes it challenging for users to distinguish between legitimate and malicious projects.

The cybersecurity community has raised concerns about the ease with which malicious actors can upload and distribute harmful code on open-source platforms like GitHub. While these platforms are invaluable resources for developers, they also present opportunities for exploitation. Experts advocate for enhanced security measures, including stricter verification processes for contributors and automated scanning for malicious code, to mitigate such risks.

In response to the GitVenom campaign, GitHub has been notified of the malicious repositories and is actively working to remove them. However, the dynamic nature of the threat necessitates continuous monitoring and prompt action to prevent further incidents.



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…