logo

200-plus impressively convincing GitHub repos are serving up malware

ID: 5f4a1996-9cf3-56f8-b7f1-18f8b9d5e4a6

STIX ID: report--5f4a1996-9cf3-56f8-b7f1-18f8b9d5e4a6

Feed Name: The Register (Security)

Threat Score
70/100

Date Published: 2025-02-26

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

Kaspersky reported a multi-year ‘GitVenom’ campaign that hosted 200+ fake GitHub repositories containing trojans, info-stealing code and crypto-wallet hijackers that have reportedly stolen nearly $500,000; CISA added two actively exploited vulnerabilities (CVE-2017-3066 in Apache BlazeDS and CVE-2024-20953 in Oracle Agile PLM) to its Known Exploited Vulnerabilities list requiring urgent patching; the digest also notes staff resignations at the renamed US Digital Service over security concerns and a LastPass client update recommended to resolve CPU issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.