2020 - 2021 Best Cryptocurrency News Investment Guide

Hackers Are Using Fake GitHub Code to Steal Your Bitcoin: Kaspersky
2025-02-27 11:25:25 Primitive Reading

 

From coindesk By Shaurya Malwa| Edited by Parikshit Mishra

What to know:

  • A Kaspersky report from Monday warned users of a “GitVenom” campaign that’s been active for at least two years but is steadily on the rise.
  • The attack starts with seemingly legitimate GitHub projects — like making Telegram bots for managing bitcoin wallets or tools for computer games.
  • One such attack ending up draining a developer's bitcoin wallet for over $400,000 worth of the token in November.

The GitHub code you use to build a trendy application or patch existing bugs might just be used to steal your bitcoin (BTC) or other crypto holdings, according to a Kaspersky report.

GitHub is popular tool among developers of all types, but even more so among crypto-focused projects, where a simple application may generate millions of dollars in revenue.

The report warned users of a “GitVenom” campaign that’s been active for at least two years but is steadily on the rise, involving planting malicious code in fake projects on the popular code repository platform.

The attack starts with seemingly legitimate GitHub projects — like making Telegram bots for managing bitcoin wallets or tools for computer games.

Each comes with a polished README file, often AI-generated, to build trust. But the code itself is a Trojan horse: For Python-based projects, attackers hide nefarious script after a bizarre string of 2,000 tabs, which decrypts and executes a malicious payload.

For JavaScript, a rogue function is embedded in the main file, triggering the launch attack. Once activated, the malware pulls additional tools from a separate hacker-controlled GitHub repository.

(A tab organizes code, making it readable by aligning lines. The payload is the core part of a program that does the actual work — or harm, in malware’s case.)

Once the system is infected, various other programs kick in to execute the exploit. A Node.js stealer harvests passwords, crypto wallet details, and browsing history, then bundles and sends them via Telegram. Remote access trojans like AsyncRAT and Quasar take over the victim’s device, logging keystrokes and capturing screenshots.

A “clipper” also swaps copied wallet addresses with the hackers’ own, redirecting funds. One such wallet netted 5 BTC — worth $485,000 at the time — in November alone.

Active for at least two years, GitVenom has hit users hardest in Russia, Brazil, and Turkey, though its reach is global, per Kaspersky.

The attackers keep it stealthy by mimicking active development and varying their coding tactics to evade antivirus software.

Disclaimer: This specification is preliminary and is subject to change at any time without notice. MYTOKEN assumes no responsibility for any errors contained herein.

Recommended reading
U.S. Bitcoin ETFs See Record Daily Outflow of Over $930M as Carry Trades Lose Shine to The 10-Year Treasury Note

10-22     admin     10699 Reading

Crypto Greed Index Flashes 'Extreme Fear' as Market Drops 10%

10-22     admin     15381 Reading

U.S. Bitcoin ETFs Post Year's 2nd-Biggest Outflows as Basis Trade Drops Below 5%

10-22     admin     16074 Reading

Bullish Crypto Bets Lose $1.2B as Bitcoin Fumbles to Under $89K, XRP Down 14%

10-22     admin     12055 Reading

This Wall Street Bitcoin Miner Just Hoarded $1.65 Billion in BTC

10-22     admin     13353 Reading

Dubai Approves Circle's Stablecoins USDC and EURC for Use in DIFC

10-22     admin     17203 Reading

Euroclear launches tokenized collateral initiative with Digital Asset

10-22     admin     16764 Reading

Robinhood says SEC dropped crypto investigation, in latest withdrawal

10-22     admin     12929 Reading

Why is Solana (SOL) price down today?

10-22     admin     11890 Reading

Montana Joins Growing List of US States Knocking Back Bitcoin Reserve Bills

10-22     admin     6788 Reading

Stablecoin Bank Infini Loses $49.5 Million in Hack, Just Days After Bybit Attack

10-22     admin     15205 Reading

Why is XRP price down today?

10-22     admin     8490 Reading

Raydium Token Dips 22% as Rumors Swirl on Pump.Fun Changes

10-22     admin     13141 Reading

Raydium token RAY ‘falling off a cliff’ as Pump.fun rumored as testing AMM

10-22     admin     14620 Reading

Bitcoin’s Weakening Network Activity Signals a Repeat of March 2024 Consolidation, Analyst Says

10-22     admin     15786 Reading