financetom
Technology
financetom
/
Technology
/
Hackers Are Using Fake GitHub Code to Steal Your Bitcoin: Kaspersky
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Hackers Are Using Fake GitHub Code to Steal Your Bitcoin: Kaspersky
Feb 25, 2025 11:36 PM

The GitHub code you use to build a trendy application or patch existing bugs might just be used to steal your bitcoin (BTC) or other crypto holdings, according to a Kaspersky report.

GitHub is popular tool among developers of all types, but even more so among crypto-focused projects, where a simple application may generate millions of dollars in revenue.

The report warned users of a “GitVenom” campaign that’s been active for at least two years but is steadily on the rise, involving planting malicious code in fake projects on the popular code repository platform.

The attack starts with seemingly legitimate GitHub projects — like making Telegram bots for managing bitcoin wallets or tools for computer games.

Each comes with a polished README file, often AI-generated, to build trust. But the code itself is a Trojan horse: For Python-based projects, attackers hide nefarious script after a bizarre string of 2,000 tabs, which decrypts and executes a malicious payload.

For JavaScript, a rogue function is embedded in the main file, triggering the launch attack. Once activated, the malware pulls additional tools from a separate hacker-controlled GitHub repository.

(A tab organizes code, making it readable by aligning lines. The payload is the core part of a program that does the actual work — or harm, in malware’s case.)

Once the system is infected, various other programs kick in to execute the exploit. A Node.js stealer harvests passwords, crypto wallet details, and browsing history, then bundles and sends them via Telegram. Remote access trojans like AsyncRAT and Quasar take over the victim’s device, logging keystrokes and capturing screenshots.

A “clipper” also swaps copied wallet addresses with the hackers’ own, redirecting funds. One such wallet netted 5 BTC — worth $485,000 at the time — in November alone.

Active for at least two years, GitVenom has hit users hardest in Russia, Brazil, and Turkey, though its reach is global, per Kaspersky.

The attackers keep it stealthy by mimicking active development and varying their coding tactics to evade antivirus software.

How can users protect themselves? By scrutinizing any code before running it, verifying the project’s authenticity, and being suspicious of overly polished READMEs or inconsistent commit histories.

Because researchers don’t expect these attacks to stop anytime soon: “We expect these attempts to continue in the future, possibly with small changes in the TTPs,” Kaspersky concluded in its post.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Taiwan Semiconductor's Options Frenzy: What You Need to Know
Taiwan Semiconductor's Options Frenzy: What You Need to Know
Jul 3, 2024
Investors with a lot of money to spend have taken a bullish stance on Taiwan Semiconductor . And retail traders should know. We noticed this today when the trades showed up on publicly available options history that we track here at Benzinga. Whether these are institutions or just wealthy individuals, we don't know. But when something this big happens with...
The Latest Analyst Ratings For Corning
The Latest Analyst Ratings For Corning
Jul 3, 2024
Analysts' ratings for Corning over the last quarter vary from bullish to bearish, as provided by 12 analysts. The table below provides a concise overview of recent ratings by analysts, offering insights into the changing sentiments over the past 30 days and drawing comparisons with the preceding months for a holistic perspective. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish Total...
A Closer Look at ASML Holding's Options Market Dynamics
A Closer Look at ASML Holding's Options Market Dynamics
Jul 3, 2024
Deep-pocketed investors have adopted a bearish approach towards ASML Holding ( ASML ) , and it's something market players shouldn't ignore. Our tracking of public options records at Benzinga unveiled this significant move today. The identity of these investors remains unknown, but such a substantial move in ASML ( ASML ) usually suggests something big is about to happen. We...
Assessing Amphenol's Performance Against Competitors In Electronic Equipment, Instruments & Components Industry
Assessing Amphenol's Performance Against Competitors In Electronic Equipment, Instruments & Components Industry
Jul 3, 2024
In the dynamic and fiercely competitive business environment, conducting a thorough analysis of companies is crucial for investors and industry enthusiasts. In this article, we will perform an extensive industry comparison, evaluating Amphenol ( APH ) in relation to its major competitors in the Electronic Equipment, Instruments & Components industry. By closely examining crucial financial metrics, market position, and growth...
Copyright 2023-2026 - www.financetom.com All Rights Reserved