logo

Hackers Hide Remcos RAT in GitHub Repository Comments

ID: b98a1f22-c1d1-56b6-af54-5b7240701d1e

STIX ID: report--b98a1f22-c1d1-56b6-af54-5b7240701d1e

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-10-09

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Trusted code-hosting platforms are being abused: attackers are embedding malware (Remcos RAT and other stealers) into GitHub repository comments to distribute malware via phishing, while an exploit for a critical GitLab SAML authentication-bypass (CVE-2024-45409) enables access as any user — together these threats risk secret exfiltration, code injection, and CI/CD manipulation across organizations using GitHub/GitLab.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.