Close Menu
Edu Expertise Hub
    Facebook X (Twitter) Instagram
    Thursday, January 29
    • About us
    • Contact
    • Submit Coupon
    Facebook X (Twitter) Instagram YouTube
    Edu Expertise Hub
    • Home
    • Udemy Coupons
    • Best Online Courses and Software Tools
      • Business & Investment
      • Computers & Internet
      • eBusiness and eMarketing
    • Reviews
    • Jobs
    • Latest News
    • Blog
    • Videos
    Edu Expertise Hub
    Home » Latest News » Cyber crooks poison GitHub search to fool developers
    Latest News

    Cyber crooks poison GitHub search to fool developers

    TeamBy TeamApril 11, 2024No Comments4 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Cyber crooks poison GitHub search to fool developers
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cyber criminals are deploying a novel technique to manipulate developers using GitHub and trick them into downloading malware, according to researchers at Checkmarx, who are warning today of a potential uptick in open source supply chain attacks as a result.

    In the campaign, an undisclosed threat actor was discovered manipulating GitHub’s search functionality by creating malicious repositories with popular names and topics, and using automated updates and fake stars to boost their search rankings on the platform.

    According to Checkmarx research engineer Yehuda Gelb, the actor hid malicious code within the repositories, contained inside csproj. and vcxproj. files, which are important elements of Visual Studio project builds, that automatically executed when the project was built. The attacker also modified the payload based on the victim’s origin, checking specifically to see if they were located in Russia, although this ability does not appear to have been switched on yet.

    The executable itself shares similarities with a malware called Keyzetsu clipper, which targets cryptocurrency wallets, and establishes persistence on infected Windows machines via the creation of a scheduled task that runs the malware daily at 4am local time, without user involvement.

    “Developers should be cautious when using code from public repositories and watch for suspicious repository properties, such as high commit frequencies and stargazers with recently created accounts,” wrote Gelb.

    Poisonous search

    The campaign discovered by Gelb is particularly notable for its sneaky exploitation of the legitimate search features within GitHub. The threat actor clearly has advanced knowledge of search optimisation techniques and uses names and topics that are likely to be searched by users, disguising them as legitimate projects that often relate to popular games, cheats or other tools.

    By exploiting GitHub Actions, they then cause the repositories to automatically update at an unusually high frequency – this is done by performing a quick modification to a log file with an updated date or time, or some other small change. This activity continuously boosts the repository’s visibility.

    The attacker also amplifies the effectiveness of their malicious repository by employing multiple sockpuppet GitHub accounts to artificially boost the malicious repository’s star ratings, boosting their visibility still further, especially to instances where users filter results by ratings.

    This is not a new technique at all, indeed it has been widely used in the past. However, in past incidents where attackers fiddled with star ratings, they tended to add hundreds or thousands of bogus ratings to their repos – in this instance they seem to be opting for more realism to avoid raising too many eyebrows.

    Gelb also noted that many of the sockpuppet stargazers were created on the same date, a potential indicator of suspicious activity.

    The malicious code itself was updated as recently as 3 April 2024 to direct to a new URL downloading a different, encrypted .7z file containing an executable called feedbackAPI.exe, so the campaign is clearly still active.

    Notably, the new executable had been padded with multiple zeros in an attempt to artificially boost its file size and exceed the threshold of scanners, such as VirusTotal, which can only accept files of up to 650MB in size – feedbackAPI.exe is 750MB in size.

    Gelb said there was enough evidence to reveal the campaign has successfully deceived a lot of people, and a number of the malicious repositories have been receiving complaints from users who were tricked into downloading the dodgy code.

    “The use of malicious GitHub repositories to distribute malware is an ongoing trend that poses a significant threat to the open source ecosystem,” wrote Gelb. “By exploiting GitHub’s search functionality and manipulating repository properties, attackers can lure unsuspecting users into downloading and executing malicious code.”

    Gelb advised GitHub users to make themselves aware of some red flags indicating a campaign of this nature might be ongoing, including repositories with an “extraordinary” number of commits relative to its age, and stargazers exhibiting sockpuppet-like behaviour.

    He argued that in the aftermath of the recent attack on the XZ Utils data compression library, in which a malicious actor apparently spent years gaining the trust of the open source project maintainer and committed many useful updates prior to trying to sneak in a backdoor, it would be unwise, if not downright irresponsible, for any developer to rely on reputation as a metric when using open source code.

    “A developer who blindly takes code also blindly takes responsibility for that code. These incidents highlight the necessity for manual code reviews or the use of specialised tools that perform thorough code inspections for malware. Merely checking for known vulnerabilities is insufficient,” he warned.

    The full research post, including indicators of compromise (IoCs), is available from Checkmarx.

    This post is exclusively published on eduexpertisehub.com

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Team

      Related Posts

      Scaling structured literacy with implementation science

      December 7, 2025

      Interview: Paul Neville, director of digital, data and technology, The Pensions Regulator

      December 7, 2025

      Students Want Power, Not Worksheets. Schools Must Teach Them to Organize.

      December 7, 2025

      Solving the staffing crisis is key to the Science of Reading movement

      December 6, 2025

      Cyber teams on alert as React2Shell exploitation spreads

      December 6, 2025

      Teaching Sex Education in Schools Is More Fraught Than Ever

      December 5, 2025
      Courses and Software Tools

      Welcome to AI: A Human Guide to Artificial Intelligence

      March 20, 2024126 Views

      Extreme Privacy: What It Takes to Disappear

      August 24, 202481 Views

      Modern C++ Programming Cookbook: Master Modern C++ with comprehensive solutions for C++23 and all previous standards

      September 18, 202434 Views

      Meebook E-Reader M7 | 6.8′ Eink Carta Screen | 300PPI Smart Light | Android 11 | Ouad Core Processor | Out Speaker | Support Google Play Store | 3GB+32GB Storage | Micro-SD Slot | Gray

      August 19, 202429 Views

      HR from the Outside In: Six Competencies for the Future of Human Resources

      May 20, 202525 Views
      Reviews

      Truth Worth Telling

      December 8, 2025

      Womens Tops Summer Sweater Short Sleeve Shirts Dressy Casual Basic Casual Cap Sleeve Tops Beach Vacation Clothes

      December 8, 2025

      The Model Thinker: What You Need to Know to Make Data Work for You

      December 8, 2025

      Scaling structured literacy with implementation science

      December 7, 2025

      How to Accept a Job Offer Professionally

      December 7, 2025
      Stay In Touch
      • Facebook
      • YouTube
      • TikTok
      • WhatsApp
      • Twitter
      • Instagram
      Latest News

      Scaling structured literacy with implementation science

      December 7, 2025

      Interview: Paul Neville, director of digital, data and technology, The Pensions Regulator

      December 7, 2025

      Students Want Power, Not Worksheets. Schools Must Teach Them to Organize.

      December 7, 2025

      Solving the staffing crisis is key to the Science of Reading movement

      December 6, 2025

      Cyber teams on alert as React2Shell exploitation spreads

      December 6, 2025
      Latest Videos

      How to Choose a Hacking Course?

      December 7, 2025

      Don’t Become a Data Analyst if

      December 6, 2025

      FC 25 vs eFootball 2025 – Graphical Details, Player Animation – Comparison! #fc25 #efootball

      December 4, 2025

      Career Game #360: Devin Booker Scoring Highlights vs BOS (02/07/2021)

      December 3, 2025

      is the CISM REQUIRED for a CYBERSECURITY career?

      December 2, 2025
      Latest Jobs

      Senior Associate, AI Data Scientist

      November 21, 2025

      Nursing Adjunct Faculty – Part-Time Nursing Instructors Needed

      November 21, 2025

      Sr. Firewall Engineer

      November 21, 2025

      Portfolio Analyst

      November 21, 2025

      Vehicle Service Specialist

      November 21, 2025
      Legal
      • Home
      • Privacy Policy
      • Cookie Policy
      • Terms and Conditions
      • Disclaimer
      • Affiliate Disclosure
      • Amazon Affiliate Disclaimer
      Latest Udemy Coupons

      ISO 9001:2015 – Quality Management System Internal Auditor | Udemy Coupons 2026

      May 5, 202537 Views

      Advanced Program in Human Resources Management | Udemy Coupons 2026

      April 5, 202536 Views

      Mastering Maxon Cinema 4D 2024: Complete Tutorial Series | Udemy Coupons 2026

      August 22, 202436 Views

      Diploma in Aviation, Airlines, Air Transportation & Airports | Udemy Coupons 2026

      March 21, 202531 Views

      Time Management and Timeboxing in Business, Projects, Agile | Udemy Coupons 2026

      April 2, 202527 Views
      Blog

      How to Accept a Job Offer Professionally

      December 7, 2025

      How to Express Gratitude Professionally

      December 6, 2025

      How to Make a Strong Impression

      December 5, 2025

      Thank-You Letter Template for Recommendation Letter: How to Express Gratitude

      December 4, 2025

      How to Track Products Without the Admin Overload –

      December 3, 2025
      Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
      © 2026 All rights reserved!

      Type above and press Enter to search. Press Esc to cancel.

      We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
      .
      SettingsAccept
      Privacy & Cookies Policy

      Privacy Overview

      This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
      Necessary
      Always Enabled
      Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
      Non-necessary
      Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
      SAVE & ACCEPT