logo

Hackers Abuse GitHub and GitLab to Host Malware and Credential Phishing Campaigns

ID: b79124d4-87ae-56b4-bf25-236b68be00d9

STIX ID: report--b79124d4-87ae-56b4-bf25-236b68be00d9

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-04-10

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Executive summary:** Threat actors are increasingly abusing trusted developer platforms (GitHub and GitLab) to host malicious files and credential phishing pages, enabling large-scale phishing campaigns that deliver Remote Access Trojans (e.g., Remcos, Byakugan, AsyncRAT, DcRAT) and info-stealers (e.g., Muck Stealer). These attacks exploit domain trust, use techniques such as password-protected archives and user-agent based delivery to evade detection, and combined malware+credential-theft campaigns are rising rapidly (2025 accounted for 45% of observed campaign volume).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.