More than 100,000 GitHub repositories infected with malware

Cybercriminals take advantage of the platform to spread malicious code

GitHub, a software development giant, becomes the target of a large-scale attack. It is a huge center for software development and stores almost 500 million code projects created by hundreds of millions of developers around the world. Given its wide reach and sheer volume of activity, the platform is fertile ground for cybercriminals, who in this case have exploited the vast network to orchestrate a malicious Python-based campaign.

The details of the attack aim to infect Python repositories with malware. The attack began in May 2023, reaching at least 100,000 affected repositories, with a potential impact on millions more.

Modus operandi:

The infection is carried out through the uploading of malicious packages to the official Python Package Index (PyPI) repository. Cloning of existing repositories and malware injection. Automatic propagation of malicious code via GitHub fork feature.

What is the function of malware?

Collects login credentials, passwords, cookies and other sensitive data. Sending stolen information to a server controlled by the attackers. Possibility of carrying out other malicious activities.

GitHub has responded that it is aware of the campaign, however the fight against this type of attack is difficult due to the large number of users and repositories. Malicious content detection and removal measures have been implemented, including manual and automatic reviews.

One of the platform’s concerns is large-scale automation that makes it difficult to contain the attack. GitHub’s success could be its biggest vulnerability. Even with a low percentage of compromised repositories, the potential damage is significant.


By: Nestor Castillo, ForAllTech Director


Discover more from ForAllTechNews

Subscribe now to keep reading and get access to the full archive.

Continue reading