logo

Hackers Post Dozens of Malicious Copycat Repos to GitHub

ID: 661e4d94-b1fd-5fc4-a8da-e89b589f5f2d

STIX ID: report--661e4d94-b1fd-5fc4-a8da-e89b589f5f2d

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2025-06-20

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

**Executive summary:** ReversingLabs and researchers observed a campaign by the cybercriminal group "Banana Squad" that posted ~67 copycat, typosquatted GitHub repositories designed to look like legitimate Python hacking tools and hide malicious payloads (including an infostealer) using obfuscation techniques such as appending code after long trailing spaces; this shift from package registries to source repositories reflects attackers adapting to improved package-security controls while continuing to pose supply-chain and credential-exposure risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.