logo

Threat Actors Increasingly Abusing GitHub for Malicious Purposes

ID: e1b28b83-586a-56bb-b035-21ee13c43954

STIX ID: report--e1b28b83-586a-56bb-b035-21ee13c43954

Feed Name: The Hacker News

Threat Score
50/100

Date Published: 2024-01-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

The report describes a growing trend where threat actors abuse GitHub and other legitimate cloud/code hosting services as "living-off-trusted-sites" (LOTS) to host payloads, act as dead-drop resolvers for C2, and sometimes for data exfiltration; it cites examples (rogue Python packages, Drokbk, ShellBox) and notes detection is difficult, recommending a mix of environment-specific detection strategies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.