Just in:
Best Mart 360 Reports Interim Revenue Growth to HK$1.45 billion // India plans own orbital space outpost, second after China // Xi reaches Cairo as China broadens Egypt engagement // Adobe widens Saudi AI access with $4 billion programme // Apple raises evidence-destruction claims against OpenAI // Delhi tops SIR deletion in percentage, Maharashtra in absolute numbers // What Shein’s $27bn IPO means for Mubadala // Drone strike damages Kuwait residential complex, no injuries // Midea to Showcase SpaceMaster Series with Graphene Technology at IFA 2026 // Macao Economic, Trade, and Tourism Investment Promotion Seminar Convened in Jakarta, Indonesia, Fostering Multi-Dimensional Cooperation to Jointly Explore New Opportunities Along the Silk Road // Putin holds talks with Pezeshkian in Bishkek // Trump rejects munitions fears as Iran clashes resume // Macao Economic, Trade and Tourism Investment Promotion Seminar Held in Singapore, Deepening Multi-Domain Cooperation to Empower Regional Growth // Hong Kong Science and Technology Parks Corporation Kicks Off 25th Anniversary Prelude “Innovation. Next by Nature.” // Qatar economy contracts 7% as energy output slumps // LatAm gushers and possible Venezuela exit a nightmare for Opec // Inovatif Media Asia Sets Regional Ambitions in Motion with Tun Ahmad Fuzi as Strategic Advisor // Ingdan, Inc. (400.HK) Announces 2026 Interim Results // XcanMow Mix 2000 Robot Mower Makes Its European Debut at IFA Berlin 2026 // Apical Provides Free Health Screenings and Treatment for Lubuk Gaung Residents //

Deceptive Development: Malicious Projects on GitHub Harbor Keyzetsu Malware

Cybersecurity researchers have uncovered a cunning scheme targeting unsuspecting developers. Threat actors are exploiting automation features on the popular code-sharing platform GitHub to distribute a new variant of the Keyzetsu malware. This malware, notorious for pilfering cryptocurrency payments, lies hidden within seemingly legitimate Visual Studio projects.

The attackers employ a two-pronged approach. First, they create repositories with names designed to rank highly in search results, often mimicking popular projects or trending topics. This increases the likelihood that developers will stumble upon the malicious code.

Secondly, the attackers leverage GitHub Actions, a built-in automation tool. GitHub Actions allows for automated tasks within repositories. In this case, the attackers exploit this functionality to constantly update the repositories with seemingly innocuous modifications. These minor changes trigger notifications and make the projects appear more active and engaging, further enticing potential victims.

However, the danger lurks beneath the surface. The seemingly innocuous project files contain embedded malware. When a developer unwittingly downloads the project and attempts to build it within Visual Studio, the malware executes silently in the background.

Keyzetsu’s primary function is to monitor the Windows clipboard, a temporary storage space for copied data. When the malware detects cryptocurrency wallet addresses copied by the victim, it surreptitiously swaps them with the attacker’s own addresses. This way, any cryptocurrency payments the victim attempts to make are unknowingly diverted to the attacker’s pockets.

Researchers warn that this campaign highlights the evolving tactics of cybercriminals who are constantly seeking new avenues to exploit. Developers are advised to exercise caution when downloading projects from unknown sources, even if they appear well-ranked or popular.

Verifying the project’s legitimacy through code reviews and developer reputation checks can help mitigate the risk. Additionally, employing robust security software that detects and blocks malware execution remains crucial.

By staying vigilant and adhering to secure coding practices, developers can fortify their defenses against these deceptive tactics and protect their systems, as well as their cryptocurrency holdings, from falling prey to this kind of malware.

____________________________________

This article first appeared on The WIRE and is brought to you by Hyphen Digital Network


(The content powered by our AI models is produced through sophisticated algorithms, and while we strive for accuracy, it may occasionally contain a few minor issues. We appreciate your understanding that AI-generated content is an evolving technology, and we encourage users to provide feedback if any discrepancies are identified. As this feature is currently in beta testing, your insights play a crucial role in enhancing the overall quality and reliability of our service. We thank you for your collaboration and understanding as we work towards delivering an increasingly refined and accurate user experience.)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


Loading next story…
Just in: