A recent report by security firm Apiiro has revealed that a “repo confusion” attack has compromised more than 100,000 repositories on GitHub.
This type of attack involves exploiting a flaw in the way that Git, the version control system used by GitHub, handles repository names and can lead to malicious code being injected into legitimate repositories.
This highlights the need for improved security measures to prevent such attacks and protect the integrity of code stored on GitHub.
This attack technique exploits the expansive scale and unguarded accessibility of the GitHub platform to launch attacks on unprepared developers.
Upon utilization of the tainted repos, unsuspecting developers inadvertently unpack a hidden payload consisting of seven layers of obfuscation.
This process involves extracting malicious Python code and an executable binary, specifically a modified version of BlackCap-Grabber.
The malevolent code is designed to collect sensitive information such as login credentials from various applications, browser-related data like passwords and cookies, as well as other confidential information.
Afterward, it transmits all the gathered data to the command-and-control server of the attackers. This sets off a cascade of additional malicious activities.
According to Apiiro’s research, an attack campaign that started in mid-2023 has been gaining momentum in recent months.
The confirmed count of infected repositories has surpassed 100,000, and there is a possibility that the actual number could be in the millions.
You can block malware, including Trojans, ransomware, spyware, rootkits, worms, and zero-day exploits, with Perimeter81 malware protection. All are extremely harmful, can wreak havoc, and damage your network.
Stay updated on Cybersecurity news, Whitepapers, and Infographics. Follow us on LinkedIn & Twitter
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…