Sunday, November 16, 2025
DIGESTWIRE
Contribute
CONTACT US
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Blog
  • Founders
No Result
View All Result
DIGESTWIRE
No Result
View All Result
Home Blockchain

Malicious GitHub repositories deploying hidden attacks on crypto wallets

by DigestWire member
February 26, 2025
in Blockchain, Crypto Market, Cryptocurrency
0
Malicious GitHub repositories deploying hidden attacks on crypto wallets
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Kaspersky researchers have identified an attack vector on GitHub that uses repositories to distribute code that targets crypto wallets.

The investigation revealed a campaign dubbed GitVenom, in which threat actors created hundreds of GitHub repositories purporting to offer utilities for social media automation, wallet management, and even gaming enhancements.

Although these repositories were designed to resemble legitimate open-source projects, their code failed to deliver the advertised functions. Instead, it embedded instructions to install cryptographic libraries, download additional payloads, and execute hidden scripts.

GitVenom repos

The malicious code appears across Python, JavaScript, C, C++, and C# projects. In Python-based repositories, a lengthy sequence of tab characters precedes commands that install packages like cryptography and fernet, ultimately decrypting and running an encrypted payload.

JavaScript projects incorporate a function that decodes a Base64-encoded script, triggering the malicious routine.

Similarly, in projects using C, C++, and C#, a concealed batch script within Visual Studio project files activates at build time. Per Kaspersky’s report, each payload is configured to fetch further components from an attacker-controlled GitHub repository.

These additional components include a Node.js stealer that collects saved credentials, digital wallet data, and browsing history before packaging the information into an archive for exfiltration via Telegram.

Open-source tools such as the AsyncRAT implant and the Quasar backdoor are also used to facilitate remote access. A clipboard hijacker that scans for crypto wallet addresses and replaces them with those controlled by the attackers is also used. 

Attack vector is not new

The campaign, which has been active for several years with some repositories originating two years ago, has triggered infection attempts worldwide. Telemetry data indicate that attempts linked to GitVenom have been most prominent in Russia, Brazil, and Turkey.

Kaspersky researchers stressed the importance of scrutinizing third-party code before execution, noting that open-source platforms, while essential to collaborative development, can also serve as conduits for malware when repositories are manipulated to mimic authentic projects.

Developers are advised to double-check the contents and activity of GitHub repositories before integrating code into their projects.

The report outlines that these projects use AI to artificially inflate commit histories and craft detailed README files. Thus, when reviewing a new repo, developers should check for overly verbose language, formulaic structure, and even leftover AI instructions or responses in these areas.

While using AI to help craft a README file is not a red flag in itself, identifying it should spur developers to investigate further before using the code. Looking for community engagement, reviews, and other projects using the repo may aid with this. However, fake AI-generated reviews and social media posts also make this a tough challenge.

The post Malicious GitHub repositories deploying hidden attacks on crypto wallets appeared first on CryptoSlate.

Read Entire Article
Tags: BlockchainCoin SurgesCryptoslate
Share30Tweet19
Next Post
BP slashes renewable investment increasing oil and gas production despite pace of global warming

BP slashes renewable investment increasing oil and gas production despite pace of global warming

Ariana Grande and Cynthia Erivo among performers at Oscars

Ariana Grande and Cynthia Erivo among performers at Oscars

Global travel ban for abuser who ‘tortured’ women in underground chamber

Global travel ban for abuser who 'tortured' women in underground chamber

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

I agree to the Terms & Conditions and Privacy Policy.

No Result
View All Result
Coins MarketCap Live Updates Coins MarketCap Live Updates Coins MarketCap Live Updates
ADVERTISEMENT

Highlights

Andre Russell released by Kolkata Knight Riders

Meghan Markle Decorates for Christmas In New Festive As Ever Video

Dan McGrath, Emmy-Winning Writer for ‘The Simpsons,’ Dies at 61

Cynthia Erivo and Ariana Grande Open Up About ‘Wicked’ Journey Following Red Carpet Scare: ‘We Have Come Through Some S—‘

Scaramucci family invested over $100M in Trump’s Bitcoin mining firm: Report

Tether Assists Global Law Enforcement in $12M Crypto Crime Bust

Trending

Luann de Lesseps Addresses BravoCon 2025 Showdown With Erika Jayne
Entertainment

Luann de Lesseps Addresses BravoCon 2025 Showdown With Erika Jayne

by DigestWire member
November 16, 2025
0

The Real Housewives of New York City alum Luann de Lesseps has revealed where she stands with...

Woman, 20, dies while kayaking in River Tees

Woman, 20, dies while kayaking in River Tees

November 16, 2025
Fundstrat’s Tom Lee Disregards Crypto Market Weakness: Pain Is ‘Short Term’

Fundstrat’s Tom Lee Disregards Crypto Market Weakness: Pain Is ‘Short Term’

November 16, 2025
Andre Russell released by Kolkata Knight Riders

Andre Russell released by Kolkata Knight Riders

November 16, 2025
Meghan Markle Decorates for Christmas In New Festive As Ever Video

Meghan Markle Decorates for Christmas In New Festive As Ever Video

November 16, 2025
DIGEST WIRE

DigestWire is an automated news feed that utilizes AI technology to gather information from sources with varying perspectives. This allows users to gain a comprehensive understanding of different arguments and make informed decisions. DigestWire is dedicated to serving the public interest and upholding democratic values.

Privacy Policy     Terms and Conditions

Recent News

  • Luann de Lesseps Addresses BravoCon 2025 Showdown With Erika Jayne November 16, 2025
  • Woman, 20, dies while kayaking in River Tees November 16, 2025
  • Fundstrat’s Tom Lee Disregards Crypto Market Weakness: Pain Is ‘Short Term’ November 16, 2025

Categories

  • Blockchain
  • Blog
  • Breaking News
  • Business
  • Cricket
  • Crypto Market
  • Cryptocurrency
  • Defense
  • Entertainment
  • Football
  • Founders
  • Health Care
  • Opinion
  • Politics
  • Sports
  • Strange
  • Technology
  • UK News
  • Uncategorized
  • US News
  • World

© 2020-23 Digest Wire. All rights belong to their respective owners.

No Result
View All Result
  • Home
  • World
  • UK
  • US
  • Breaking News
  • Technology
  • Entertainment
  • Health Care
  • Business
  • Sports
    • Sports
    • Cricket
    • Football
  • Defense
  • Crypto
    • Crypto News
    • Crypto Calculator
    • Blockchain
    • Coins Marketcap
    • Top Gainers and Loser of the day
    • Crypto Exchanges
  • Politics
  • Opinion
  • Strange
  • Blog
  • Founders
  • Contribute!

© 2024 Digest Wire - All right reserved.

Privacy Policy   Terms and Conditions

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.