logo

Hackers Abusing GitHub to Evade Detection and Control Compromised Hosts

ID: cfd0a900-0521-5a2d-8e8f-f51b9d735bba

STIX ID: report--cfd0a900-0521-5a2d-8e8f-f51b9d735bba

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2023-12-19

Date Updated: 2026-04-23

Author: [email protected] (The Hacker News)

...
...

ReversingLabs reports that threat actors are increasingly abusing GitHub features—notably secret Gists and git commit messages—as covert command-and-control channels and dead-drop resolvers. Several malicious PyPI packages masquerading as proxy/network libraries contained Base64-encoded URLs or commit-message payloads that, when decoded, executed commands on infected hosts; the fraudulent packages were removed from PyPI. This technique lets attackers blend malicious C2 traffic with legitimate GitHub activity, complicating detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.