'Water Curse' Targets Infosec Pros via Poisoned GitHub Repositories
ID: 454c6c63-5979-5a50-9659-59e65c08ad0a
STIX ID: report--454c6c63-5979-5a50-9659-59e65c08ad0a
Feed Name: Dark Reading
Date Published: 2025-06-16
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Water Curse is an emerging threat group weaponizing GitHub repositories by embedding malicious build-script payloads into seemingly legitimate pentesting and developer tools; the multistage malware (PreBuildEvent → VBScript → obfuscated PowerShell) harvests credentials, browser data and session tokens, provides remote access, and persists on infected hosts, posing a software-supply-chain risk to developers, security professionals and DevOps teams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
