GitGot: GitHub leveraged by cybercriminals to store stolen data
ID: 6d7b0e96-2d8e-5eab-a2e9-46afb375f824
STIX ID: report--6d7b0e96-2d8e-5eab-a2e9-46afb375f824
Feed Name: ReversingLabs Blog
ReversingLabs discovered two malicious npm packages (warbeast2000 and kodiak2k) that executed postinstall scripts to read SSH private keys (e.g., id_rsa or a file named “meow”) from users' ~/.ssh directories, Base64-encoded the keys, and uploaded them to attacker-controlled GitHub repositories; kodiak2k also exhibited references to the Empire framework and Mimikatz in later versions, suggesting additional post-exploitation capabilities. Both packages were reported and removed from npm after limited distribution (~400 and ~950 downloads), but the campaign highlights growing abuse of open-source package ecosystems and GitHub for data exfiltration and command-and-control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
