logo

GitGot: GitHub leveraged by cybercriminals to store stolen data

ID: 6d7b0e96-2d8e-5eab-a2e9-46afb375f824

STIX ID: report--6d7b0e96-2d8e-5eab-a2e9-46afb375f824

Feed Name: ReversingLabs Blog

Threat Score
65/100

Date Published: 2024-01-23

Date Updated: 2026-04-29

Author: [email protected] (Lucija Valentić)

...
...

ReversingLabs discovered two malicious npm packages (warbeast2000 and kodiak2k) that executed postinstall scripts to read SSH private keys (e.g., id_rsa or a file named “meow”) from users' ~/.ssh directories, Base64-encoded the keys, and uploaded them to attacker-controlled GitHub repositories; kodiak2k also exhibited references to the Empire framework and Mimikatz in later versions, suggesting additional post-exploitation capabilities. Both packages were reported and removed from npm after limited distribution (~400 and ~950 downloads), but the campaign highlights growing abuse of open-source package ecosystems and GitHub for data exfiltration and command-and-control.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.