GitHub comments abused to push malware via Microsoft repo URLs
ID: 2b79a581-276b-5cac-abc0-e993be04ab7d
STIX ID: report--2b79a581-276b-5cac-abc0-e993be04ab7d
Feed Name: Bleeping Computer
Threat Score
Researchers observed threat actors abusing GitHub's comment file upload mechanism to host malware (including a LUA loader called SmartLoader and the RedLine infostealer) using URLs that appear to belong to trusted repositories (e.g., Microsoft projects), enabling convincing lures and persistent distribution since the CDN links remain active even if comments are removed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
