#GitHub
Malware/Tool
2023-03-21 • The Unintentional Leak: A glimpse into the attack vectors of APT37
GitHub is a legitimate source-code and repository-hosting service, not a malware family. DPRK-linked operations abused repositories, release artifacts, developer accounts, and raw-content hosting to distribute malicious dependencies, support fake coding tests, poison software projects, and stage encrypted payloads. PolinRider compromised or forked thousands of repositories and injected JavaScript into build-related configuration files, while another fake-interview operation used a trojanized repository whose Node.js backdoor collected system and environment data, executed remote commands, and beaconed every five seconds.
-
27
Tagged Reports
-
17
Unique Authors
-
1,257
Active Days