GitHub struggles to keep up with automated malicious forks
ID: de629ef9-8641-55a4-b521-976bf76810dc
STIX ID: report--de629ef9-8641-55a4-b521-976bf76810dc
Feed Name: The Register (Security)
Threat Score
A widespread supply-chain malware campaign started with malicious Python packages and moved to GitHub, where adversaries cloned and poisoned legitimate repositories with a modified BlackCap-Grabber infostealer that steals credentials and exfiltrates data to C2 servers; attackers automated account/repo creation, mass-forking (resulting in at least ~100,000 compromised repositories), and used evasion techniques like "exec smuggling" to hamper detection and manual review.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
