GitHub under attack — millions of malicious cloud repositories bombard website

GitHub Webpage
(Image credit: Gil C / Shutterstock)

Hackers have found a way to automate duplicating malicious GitHub packages, bombarding the open source cloud repository with millions of repos capable of stealing sensitive information and information cookies.

Cybersecurity researchers from Apiiro Matan Giladi and Gil David explained how since the middle of 2023, hackers have engaged in a typosquatting attack against software developers on an enormous scale. First, they would clone an existing repository, possibly one that’s popular among the developers (such as WhatsappBOT, discord-boost-too, and similar), and infect it with a malware loader.

The loader, hidden behind seven layers of obfuscation, drops a modified version of the open source BlackCap-Grabber. This infostealer grabs authentication cookies and login credentials from a wide array of apps, and sends them to a server under the attackers’ control. BlackCap-Grabber also performs “a long series of additional malicious activities,” the researchers added.

Hundreds of thousands of repos

Once the loader is set up and in place, the attackers will upload it back to GitHub with an identical name, in an attempt to get unsuspecting developers to download the wrong one. Then, they would automatically fork the repository thousands of times, resulting in hundreds of thousands of malicious repositories sitting on the platform. The attack impacted more than 100,000 GitHub repositories, the researchers said, speculating that the actual number is in the millions. 

Finally, the attackers would promote the malicious packages on the web, in different forums, discord channels, and similar, to get as many people to download them.

To make matters even worse, some developers started forking the malicious forks themselves, unknowingly further propagating the campaign.

GitHub has a way to tackle the problem, it was said. Using artificial intelligence, it manages to stop the vast majority of cloned packages before ever reaching the platform. However, 1% survive, amounting to “thousands of malicious repos” it was said.

Via Ars Technica

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
A graphic showing someone on a tablet working through a supply chain.
Security issue in open source software leaves businesses concerned for systems
GitHub Webpage
A cracked malicious version of a Go package lay undetected online for years
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Microsoft reveals over a million PCs hit by malvertising campaign
Latest in Security
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Latest in News
IBM office logo
IBM to provide platform for flagship cyber skills programme for girls
Apple iPhone 16 Review
New iPhone 17 report lends weight to rumors of major display and camera upgrades, and a pricey Apple foldable
Teams
Microsoft Teams is finally adding a tiny but crucial feature I honestly can't believe it never had
Apple Watch Ultra 2 move data
Apple is reportedly planning a huge future Apple Watch upgrade to turn it into an AI device with onboard cameras
Apple watch pair with iphone
The Apple Watch SE 3 is apparently in 'serious jeopardy', and the news isn't much better for the Ultra 3 or Series 11
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025