Malware leveraging public infrastructure like GitHub on the rise
ID: 8fa3b352-75b9-5b07-81a8-a1bf548e6a9b
STIX ID: report--8fa3b352-75b9-5b07-81a8-a1bf548e6a9b
Feed Name: ReversingLabs Blog
Threat Score
Executive summary: ReversingLabs discovered a software supply-chain campaign where malicious PyPI packages hide code in setup.py to fetch and execute payloads or commands hosted on GitHub — notably using secret Gists and Base64-encoded git commit messages as C2/payload delivery mechanisms — delivering infostealer and RAT second stages and providing IOCs for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
