logo

Malicious Visual Studio projects on GitHub push Keyzetsu malware

ID: ec5914d9-05f5-5fb8-ba95-35e620423fd9

STIX ID: report--ec5914d9-05f5-5fb8-ba95-35e620423fd9

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2024-04-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors are abusing GitHub automation and malicious Visual Studio project files to distribute a variant of the Keyzetsu clipboard-hijacker that replaces copied cryptocurrency addresses. The campaign boosts repository visibility using GitHub Actions and fake stars, hides payload execution in PreBuildEvent scripts that run batch and base64 PowerShell stagers, delivers an encrypted/7z payload padded to ~750MB to evade scanners, and creates a scheduled task (Feedback_API_VS_Services_Client) for persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.