The GitVenom campaign: cryptocurrency theft using GitHub


In our modern world, it’s difficult to underestimate the impact that open-source code has on software development. Over the years, the global community has managed to publish a tremendous number of projects with freely accessible code that can be viewed and enhanced by anyone on the planet.

With more and more open-source projects being published, both state-sponsored actors and cybercriminals started using freely available code as a lure to infect their targets. Of course, this trend shows no sign of slowing down as evidenced by a currently active campaign aimed at GitHub users that Kaspersky researchers dubbed GitVenom.

Read more…
Source: Kaspersky


Sign up for our Newsletter


Related:

  • P&O Ferries data blunder as it sends out passengers’ personal details by text message

    August 31, 2026

    P&O Ferries was hit by a data breach after mistakenly sending out a full list of passengers’ personal details by text message this morning, we can reveal. A blunder saw the details of 432 passengers travelling on the 12pm P&O ferry from Calais to Dover sent as an attachment in a customer services text message. It is ...

  • ValleyRAT masquerading as adware

    August 31, 2026

    Attackers typically try to pass off malware as legitimate applications or as potentially unwanted programs that users deliberately search for and download, such as cheats or cracks. They often rely on ad and affiliate networks to deliver their creations to victims’ devices. This post examines a less conventional case: a well-known backdoor distributed under the ...

  • Healthcare data breach exposes 3.75M patient records

    August 30, 2026

    Hackers stole medical records, Social Security numbers, government IDs and financial data from millions of CareCloud patients You can be careful with your passwords and still get caught in a breach at a company you may have never heard of. That is one of the frustrating parts of the CareCloud data breach. More than 3.75 million ...

  • TerminalFix campaign deploys a reverse tunnel through multistage intrusion

    August 28, 2026

    Microsoft Threat Intelligence has observed a TerminalFix campaign, a variant of ClickFix, targeting organizations across multiple industries. The campaign uses compromised websites to display a fake Cloudflare CAPTCHA verification overlay that tricks users into copying and executing a malicious PowerShell command. While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply ...

  • Australian police arrest alleged TeamPCP masterminds

    August 28, 2026

    The Australian city of Perth is by some measures the world’s most isolated major metropolis, but is still sufficiently connected to US law enforcement authorities that the FBI was able to help Australia’s Federal Police (AFP) to find two men they believe were the masterminds of TeamPCP, a cybercrime crew that conducted prominent supply chain ...

  • Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs

    August 27, 2026

    Despite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft reports annually, with related fraud and imposter scams accounting for billions in financial losses each year. While stolen credit cards enable rapid, short-term monetization, Social ...