GitHub under attack — millions of malicious cloud repositories bombard website

github under attack — millions of malicious cloud repositories bombard website

GitHub under attack — millions of malicious cloud repositories bombard website

Hackers have found a way to automate duplicating malicious GitHub packages, bombarding the open source cloud repository with millions of repos capable of stealing sensitive information and information cookies.

Cybersecurity researchers from Apiiro Matan Giladi and Gil David explained how since the middle of 2023, hackers have engaged in a typosquatting attack against software developers on an enormous scale. First, they would clone an existing repository, possibly one that’s popular among the developers (such as WhatsappBOT, discord-boost-too, and similar), and infect it with a malware loader.

The loader, hidden behind seven layers of obfuscation, drops a modified version of the open source BlackCap-Grabber. This infostealer grabs authentication cookies and login credentials from a wide array of apps, and sends them to a server under the attackers’ control. BlackCap-Grabber also performs “a long series of additional malicious activities,” the researchers added.

Hundreds of thousands of repos

Once the loader is set up and in place, the attackers will upload it back to GitHub with an identical name, in an attempt to get unsuspecting developers to download the wrong one. Then, they would automatically fork the repository thousands of times, resulting in hundreds of thousands of malicious repositories sitting on the platform. The attack impacted more than 100,000 GitHub repositories, the researchers said, speculating that the actual number is in the millions.

Finally, the attackers would promote the malicious packages on the web, in different forums, discord channels, and similar, to get as many people to download them.

To make matters even worse, some developers started forking the malicious forks themselves, unknowingly further propagating the campaign.

GitHub has a way to tackle the problem, it was said. Using artificial intelligence, it manages to stop the vast majority of cloned packages before ever reaching the platform. However, 1% survive, amounting to “thousands of malicious repos” it was said.

Via Ars Technica

More from TechRadar Pro

    News Related

    OTHER NEWS

    FA confident that Man Utd starlet will pick England over Ghana

    Kobbie Mainoo made his first start for Man Utd at Everton (Photo: Getty) The Football Association are reportedly confident that Manchester United starlet Kobbie Mainoo will choose to represent England ... Read more »

    World Darts Championship draw throws up tricky tests for big names

    Michael Smith will begin the defence of his world title on the opening night (Picture: Getty Images) The 2024 World Darts Championship is less than three weeks away and the ... Read more »

    Pioneering flight to use repurposed cooking oil to cross Atlantic

    For the first time a long haul commercial aircraft is flying across the Atlantic using 100% sustainable aviation fuel (SAF). A long haul commercial flight is flying to the US ... Read more »

    King meets world business and finance figures at Buckingham Palace

    The King has met business and finance leaders from across the world at a Buckingham Palace reception to mark the conclusion of the UK’s Global Investment Summit. Charles was introduced ... Read more »

    What Lou Holtz thinks of Ohio State's loss to Michigan: 'They aren't real happy'

    After Ohio State’s 30-24 loss to Michigan Saturday, many college football fans were wondering where Lou Holtz was. In his postgame interview after the Buckeyes beat Notre Dame 17-14 in ... Read more »

    Darius Slay wouldn't have minded being penalized on controversial no-call

    Darius Slay wouldn’t have minded being penalized on controversial no-call No matter which team you were rooting for on Sunday, we can all agree that the officiating job performed by ... Read more »

    Mac Jones discusses Patriots future after latest benching

    New England Patriots quarterback Mac Jones (10) Quarterback Mac Jones remains committed to finding success with the New England Patriots even though his future is up in the air following ... Read more »
    Top List in the World