Hackers Post Dozens of Malicious Copycat Repos to GitHub
ID: 661e4d94-b1fd-5fc4-a8da-e89b589f5f2d
STIX ID: report--661e4d94-b1fd-5fc4-a8da-e89b589f5f2d
Feed Name: Dark Reading
**Executive summary:** ReversingLabs and researchers observed a campaign by the cybercriminal group "Banana Squad" that posted ~67 copycat, typosquatted GitHub repositories designed to look like legitimate Python hacking tools and hide malicious payloads (including an infostealer) using obfuscation techniques such as appending code after long trailing spaces; this shift from package registries to source repositories reflects attackers adapting to improved package-security controls while continuing to pose supply-chain and credential-exposure risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
