GitHub comments abused to push password stealing malware masked as fixes
ID: da45dcac-f3bc-5076-87e9-1c39b16218b9
STIX ID: report--da45dcac-f3bc-5076-87e9-1c39b16218b9
Feed Name: Bleeping Computer
A widespread campaign has been abusing GitHub issue comments to post fake "fixes" that link to password-protected archives (password: "changeme") hosting an executable identified as the Lumma Stealer info-stealer. The malware harvests browser credentials, cookies, credit cards, and cryptocurrency wallets/private keys, bundles the data, and exfiltrates it to attackers; researchers observed thousands of comments (reported ~29,000 over three days) across many projects and provided indicators and remediation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
