logo

More than a hundred backdoored malware repos traced to single GitHub user

ID: c13ca06a-ca67-5033-b1c6-7114910722af

STIX ID: report--c13ca06a-ca67-5033-b1c6-7114910722af

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2025-06-05

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Sophos investigators uncovered a large-scale campaign attributed to 'ischhfd83' that created and automated hundreds of GitHub repositories—many marketed as game cheats or tools—but backdoored to install infostealers, RATs and other malware via PreBuild events and GitHub Actions; the activity (141 repos examined, 133 backdoored) appears to function as a distribution-as-a-service targeting novice cybercriminals and cheaters and has links to similar supply-chain efforts tracked since 2022.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.