logo

'Water Curse' Targets Infosec Pros via Poisoned GitHub Repositories

ID: 454c6c63-5979-5a50-9659-59e65c08ad0a

STIX ID: report--454c6c63-5979-5a50-9659-59e65c08ad0a

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2025-06-16

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Water Curse is an emerging threat group weaponizing GitHub repositories by embedding malicious build-script payloads into seemingly legitimate pentesting and developer tools; the multistage malware (PreBuildEvent → VBScript → obfuscated PowerShell) harvests credentials, browser data and session tokens, provides remote access, and persists on infected hosts, posing a software-supply-chain risk to developers, security professionals and DevOps teams.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.