Privacy News Hacker Breaches Syscoin GitHub Account and Poisons Official Client

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
A hacker gained access to the GitHub account of the Syscoin cryptocurrency and replaced the official Windows client with a version containing malware.

The poisoned Syscoin Windows client contained Arkei Stealer, a malware strain specialized in dumping and stealing passwords and wallet private keys. This malware is also detected as Trojan:Win32/Feury.B!cl.

Syscoin developers are now warning Syscoin users who downloaded version 3.0.4.1 of the Syscoin client between June 09th, 2018 10:14 PM UTC and June 13th, 2018 10:23 PM UTC that their systems might be infected with malware.

The affected files are (version number included in the file name is 3.0.4, but they install version 3.0.4.1):

syscoincore-3.0.4-win32-setup.exe
syscoincore-3.0.4-win64-setup.exe

Only Syscoin Windows client affected

Hackers only tampered with the Windows client and no other files available in the v3.0.4.1 release, which also included Mac and Linux clients, along with the adjacent source code.

The Syscoin clients are installed on an operating system and allow users to run a Syscoin node, which they can use to mine new Syscoin cryptocurrency or manage Syscoin funds.

The incident came to light yesterday when the Syscoin team received a warning from users that Windows Defender SmartScreen was marking downloads of the Syscoin Windows client as malicious.
What users need to do

After a thorough investigation of the report, the Syscoin team discovered that a hacker compromised one of its developers' GitHub accounts, and took actions to remove the malicious files and warn users.

...
.....
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top