financetom
Technology
financetom
/
Technology
/
Hackers Are Using Fake GitHub Code to Steal Your Bitcoin: Kaspersky
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Hackers Are Using Fake GitHub Code to Steal Your Bitcoin: Kaspersky
Feb 25, 2025 11:36 PM

The GitHub code you use to build a trendy application or patch existing bugs might just be used to steal your bitcoin (BTC) or other crypto holdings, according to a Kaspersky report.

GitHub is popular tool among developers of all types, but even more so among crypto-focused projects, where a simple application may generate millions of dollars in revenue.

The report warned users of a “GitVenom” campaign that’s been active for at least two years but is steadily on the rise, involving planting malicious code in fake projects on the popular code repository platform.

The attack starts with seemingly legitimate GitHub projects — like making Telegram bots for managing bitcoin wallets or tools for computer games.

Each comes with a polished README file, often AI-generated, to build trust. But the code itself is a Trojan horse: For Python-based projects, attackers hide nefarious script after a bizarre string of 2,000 tabs, which decrypts and executes a malicious payload.

For JavaScript, a rogue function is embedded in the main file, triggering the launch attack. Once activated, the malware pulls additional tools from a separate hacker-controlled GitHub repository.

(A tab organizes code, making it readable by aligning lines. The payload is the core part of a program that does the actual work — or harm, in malware’s case.)

Once the system is infected, various other programs kick in to execute the exploit. A Node.js stealer harvests passwords, crypto wallet details, and browsing history, then bundles and sends them via Telegram. Remote access trojans like AsyncRAT and Quasar take over the victim’s device, logging keystrokes and capturing screenshots.

A “clipper” also swaps copied wallet addresses with the hackers’ own, redirecting funds. One such wallet netted 5 BTC — worth $485,000 at the time — in November alone.

Active for at least two years, GitVenom has hit users hardest in Russia, Brazil, and Turkey, though its reach is global, per Kaspersky.

The attackers keep it stealthy by mimicking active development and varying their coding tactics to evade antivirus software.

How can users protect themselves? By scrutinizing any code before running it, verifying the project’s authenticity, and being suspicious of overly polished READMEs or inconsistent commit histories.

Because researchers don’t expect these attacks to stop anytime soon: “We expect these attempts to continue in the future, possibly with small changes in the TTPs,” Kaspersky concluded in its post.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Nvidia Delivered 'Jaw Dropping' Q3 Earnings, Says Dan Ives: 'This Is The Fourth Revolution Playing Out In Front Of Our Eyes'
Nvidia Delivered 'Jaw Dropping' Q3 Earnings, Says Dan Ives: 'This Is The Fourth Revolution Playing Out In Front Of Our Eyes'
Nov 20, 2024
Nvidia Corp. ( NVDA ) has once again defied market expectations, delivering a blockbuster third-quarter performance that tech analysts are calling a watershed moment for artificial intelligence. What Happened: Wedbush Securities Managing Director Dan Ives described the results as a “jaw-dropper,” emphasizing the transformative potential of the company’s AI technology. “This is the fourth revolution playing out in front of...
Trump picks Wall St CEO Lutnick to run Commerce, oversee USTR, tariffs
Trump picks Wall St CEO Lutnick to run Commerce, oversee USTR, tariffs
Nov 20, 2024
WASHINGTON (Reuters) -U.S. President-elect Donald Trump said on Tuesday he will nominate Wall Street CEO Howard Lutnick to lead his trade and tariff strategy as head of the Commerce Department, the agency that has become the U.S. weapon of choice against China's tech sector. Lutnick, the head of brokerage firm Cantor Fitzgerald, will also have additional direct responsibility for the...
Elon Musk's Neuralink receives Canadian approval for brain chip trial
Elon Musk's Neuralink receives Canadian approval for brain chip trial
Nov 20, 2024
(Reuters) - Elon Musk's Neuralink said on Wednesday it has received approval to launch its first clinical trial in Canada for a device designed to give paralysed individuals the ability to use digital devices simply by thinking. The brain chip startup said the Canadian study aims to assess the safety and initial functionality of its implant which enables people with...
Britain imposes asset freeze, travel ban on Angola's Isabel dos Santos
Britain imposes asset freeze, travel ban on Angola's Isabel dos Santos
Nov 21, 2024
LONDON (Reuters) - Britain has imposed a travel ban and an asset freeze on Angolan billionaire Isabel dos Santos under its global anti-corruption sanctions regime, the British government said on Thursday. Dos Santos, whose father Jose Eduardo dos Santos ruled Angola for 38 years until 2017, has faced corruption accusations in Angola and elsewhere for years. Africa's first female billionaire...
Copyright 2023-2025 - www.financetom.com All Rights Reserved