logo

GitHub Developers Hit in Complex Supply Chain Cyberattack

ID: 8efb7a6d-f453-5257-b3b8-b90a280b6dc9

STIX ID: report--8efb7a6d-f453-5257-b3b8-b90a280b6dc9

Feed Name: Dark Reading

Threat Score
88/100

Date Published: 2024-03-25

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

An unidentified threat group executed a sophisticated software supply-chain campaign against the Top.gg GitHub organization and open-source Python packages by hijacking developer accounts (via stolen cookies), pushing verified malicious commits, creating a fake PyPI mirror, and publishing tainted packages (notably impacting Colorama). The delivered malware uses obfuscation, persistence mechanisms, and data-stealing capabilities to exfiltrate browser cookies, autofill data, credentials, Discord tokens, cryptocurrency wallets, Telegram session data, and Instagram information; abused domains were taken down but the threat is considered active.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.