logo

GitHub comments abused to push malware via Microsoft repo URLs

ID: 2b79a581-276b-5cac-abc0-e993be04ab7d

STIX ID: report--2b79a581-276b-5cac-abc0-e993be04ab7d

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-20

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Researchers observed threat actors abusing GitHub's comment file upload mechanism to host malware (including a LUA loader called SmartLoader and the RedLine infostealer) using URLs that appear to belong to trusted repositories (e.g., Microsoft projects), enabling convincing lures and persistent distribution since the CDN links remain active even if comments are removed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.