Security News GitHub besieged by millions of malicious repositories in ongoing attack

MuzzMelbourne

Level 15
Thread author
Verified
Top Poster
Well-known
Mar 13, 2022
599
GitHub is struggling to contain an ongoing attack that’s flooding the site with millions of code repositories. These repositories contain obfuscated malware that steals passwords and cryptocurrency from developer devices, researchers said.

The malicious repositories are clones of legitimate ones, making them hard to distinguish to the casual eye. An unknown party has automated a process that forks legitimate repositories, meaning the source code is copied so developers can use it in an independent project that builds on the original one. The result is millions of forks with names identical to the original one that add a payload that’s wrapped under seven layers of obfuscation. To make matters worse, some people, unaware of the malice of these imitators, are forking the forks, which adds to the flood.
 

Can't Decide

Level 1
Dec 15, 2023
28
Researchers just said it affacting developer devices but will it also affact anyone that download and use the code on their devices? :eek:
Can the appliction that are affacted be detected or prevent it from infecting PC?

Just to be safe, for the time being better not download anything from Github until it contain and clear of repositories that contain obfuscated malware.
 

Can't Decide

Level 1
Dec 15, 2023
28
Researchers just said it affacting developer devices but will it also affact anyone that download and use the code on their devices? :eek:
Can the appliction that are affacted be detected or prevent it from infecting PC?

Just to be safe, for the time being better not download anything from Github until it contain and clear of repositories that contain obfuscated malware.
Can't edit anymore...

Can the appliction that are affacted be detected or prevent it from infecting PC and Phone?
And will it affact installed program or app (especially those security & privacy app in PlayStore) that are from Github before this ongoing attack happen?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top