Hackers Compromised 10,000+ GitHub Repositories to Inject Malicious Script
ID: e94794ca-57a0-57b8-8f5b-de00f38605f2
STIX ID: report--e94794ca-57a0-57b8-8f5b-de00f38605f2
Feed Name: cybersecurityNews.com
A researcher uncovered a large-scale GitHub malware campaign in which attackers cloned legitimate repositories (preserving commit history and contributor metadata) and periodically inserted README links to ZIP archives that contained Trojan malware. The operation used evasion techniques—including splitting payloads across files and repeatedly updating README commits—to reduce automated detection, and an analysis of GH Archive data identified approximately 10,000 affected repositories that had remained undetected for extended periods.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
