logo

Hackers Hijack GitHub Accounts in Supply Chain Attack Affecting Top-gg and Others

ID: 3ef3b791-2d41-5618-9da0-11e95c21f341

STIX ID: report--3ef3b791-2d41-5618-9da0-11e95c21f341

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-03-25

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Unidentified adversaries ran a supply-chain campaign by hosting trojanized Python packages on a typosquatted PyPI mirror (files.pypihosted.org) and performing GitHub account takeovers (via stolen browser cookies) to commit malicious changes to repositories' requirements.txt; the malicious colorama package (a widely used library) triggered a multi-stage infostealer that fetches remote code, persists via Windows Registry changes, and exfiltrates credentials, browser data, crypto wallets, and messaging tokens to anonymous file-sharing services or attacker infrastructure—Cloudflare and repository maintainers have since removed the fake domain and some malicious repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.