logo

GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure

ID: 78507cd9-74ef-5b51-9a89-0627e35d1630

STIX ID: report--78507cd9-74ef-5b51-9a89-0627e35d1630

Feed Name: Recorded Future Blog

Threat Score
72/100

Date Published: 2024-05-14

Date Updated: 2026-04-28

...
...

Recorded Future's Insikt Group uncovered a coordinated cybercriminal campaign in which Russian-speaking actors abused GitHub to host counterfeit installers of legitimate macOS apps (e.g., 1Password, Bartender 5, Pixelmator Pro) to distribute multiple info-stealer malware families (Atomic macOS Stealer/AMOS, Vidar, Lumma, Octo). Analysis revealed a shared command-and-control infrastructure suggesting organized operations; the report warns that trusted developer platforms are being weaponized and recommends organization-wide code review, automated scanning tools, and enhanced monitoring of unauthorized applications.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.