logo

Malware leveraging public infrastructure like GitHub on the rise

ID: 8fa3b352-75b9-5b07-81a8-a1bf548e6a9b

STIX ID: report--8fa3b352-75b9-5b07-81a8-a1bf548e6a9b

Feed Name: ReversingLabs Blog

Threat Score
70/100

Date Published: 2023-12-19

Date Updated: 2026-04-29

Author: [email protected] (Karlo Zanki)

...
...

Executive summary: ReversingLabs discovered a software supply-chain campaign where malicious PyPI packages hide code in setup.py to fetch and execute payloads or commands hosted on GitHub — notably using secret Gists and Base64-encoded git commit messages as C2/payload delivery mechanisms — delivering infostealer and RAT second stages and providing IOCs for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.