The GitVenom campaign: cryptocurrency theft using GitHub
ID: 6c97d759-cce2-5348-83d7-cefb0a15aec7
STIX ID: report--6c97d759-cce2-5348-83d7-cefb0a15aec7
Feed Name: Securelist by Kaspersky
GitVenom is an active campaign that lures developers with fake GitHub projects containing hidden loaders in multiple languages; the malicious repos download and execute payloads including a Node.js stealer (exfiltrates credentials and wallets), AsyncRAT and Quasar implants, and a clipboard hijacker. The actors used polished READMEs, frequent commits, and build-time execution to appear legitimate; telemetry shows global infection attempts (notably Russia, Brazil, Turkey) and confirmed financial theft (~5 BTC). Reference hashes for infected repository archives are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
