#GitHub

Malware/Tool

2023-03-21 • The Unintentional Leak: A glimpse into the attack vectors of APT37

GitHub is a legitimate source-code and repository-hosting service, not a malware family. DPRK-linked operations abused repositories, release artifacts, developer accounts, and raw-content hosting to distribute malicious dependencies, support fake coding tests, poison software projects, and stage encrypted payloads. PolinRider compromised or forked thousands of repositories and injected JavaScript into build-related configuration files, while another fake-interview operation used a trojanized repository whose Node.js backdoor collected system and environment data, executed remote commands, and beaconed every five seconds.

Tagged Reports

« Back