Home ยป Challenges on GitHub: Hackers Creating Fake Repositories with Malware to Deceive Users Into Downloading

Challenges on GitHub: Hackers Creating Fake Repositories with Malware to Deceive Users Into Downloading

Apiiro, a cybersecurity company, has reported that GitHub is currently under attack using a method of creating fake repositories embedded with malware. There are over 100,000 of these fake repositories.

The attack method involves cloning real repositories, embedding malware files, and then uploading them back to GitHub using the same repository name (but in different project accounts). These fake repositories are then promoted on forums and social media platforms in an attempt to confuse software developers (repo confusions) into downloading and running the malware code.

Apiiro has stated that GitHub’s automated detection system can delete many of these fake repositories, but some are still slipping through the cracks. This wave of fake repository creation began towards the end of 2023 and is still ongoing. Currently, there is no information on which hacker group is behind this attack.

Source: Apiiro via Ars Technica

TLDR: GitHub is facing a large-scale attack where fake repositories containing malware are being created and promoted to deceive developers. Despite efforts to delete these fake repositories, some are still managing to evade detection. The origin of the attack remains unknown.

More Reading

Post navigation

Leave a Comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Revolutionizing the IoT Landscape: BlackBerry Transforms into a Cutting-Edge Enterprise, Paving its Path Away from Core Cybersecurity Operations

MicroSoft’s MS-DOS 4.0 Open Source Initiative Lands Source Code on GitHub.

Nearly 6 out of 10 victims of sexual crimes in South Korea are minors targeted by Deepfake technology.