AUTO-UPDATED

I found 10k GitHub repositories distributing Trojan malware

A security researcher has identified a large-scale malware campaign involving 10,000 GitHub repositories that distribute Trojan-infected zip archives by mimicking legitimate project structures to deceive unsuspecting software developers.

Key Points

  • The campaign uses automated scripts to clone legitimate repositories, adding malicious zip files to readme updates.
  • Malicious archives contain executable files that bypass VirusTotal detection but install Trojans upon execution.
  • Attackers frequently overwrite commit histories to evade GitHub’s automated security detection and indexing algorithms.
  • The researcher utilized the gharchive service to analyze GitHub event data and identify 10,000 active malicious repositories.
  • GitHub has historically relied on manual reports for removal, failing to proactively identify or purge the automated distribution network.

Why it Matters

This discovery highlights a significant vulnerability in software supply chain security where attackers exploit repository cloning to distribute malware through trusted platforms. The persistence of this campaign suggests that current automated moderation tools are insufficient to detect sophisticated, high-volume social engineering tactics on major code-hosting services.
Orchidfiles.com Published by Orchid
Read original