logo

Hackers Use Fake PoCs on GitHub to Steal WordPress Credentials, AWS Keys

ID: 85919ba1-6ac8-5c00-a2e0-31515ebc6270

STIX ID: report--85919ba1-6ac8-5c00-a2e0-31515ebc6270

Feed Name: HackRead

Threat Score
76/100

Date Published: 2024-12-17

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

### Executive Summary Datadog Security Labs discovered a year-long campaign by actor MUT-1244 that lured security researchers and practitioners with trojanized proof-of-concept code on GitHub and targeted academics via phishing; attackers deployed droppers, backdoored configs, malicious PDFs and npm packages to steal sensitive data, exfiltrating over 390,000 WordPress credentials plus AWS keys, SSH private keys, and command histories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.