A security researcher has identified a large-scale malware campaign involving 10,000 GitHub repositories that distribute Trojan-infected zip archives by mimicking legitimate project structures to deceive unsuspecting software developers.
Key Points
- The campaign uses automated scripts to clone legitimate repositories, adding malicious zip files to readme updates.
- Malicious archives contain executable files that bypass VirusTotal detection but install Trojans upon execution.
- Attackers frequently overwrite commit histories to evade GitHub’s automated security detection and indexing algorithms.
- The researcher utilized the gharchive service to analyze GitHub event data and identify 10,000 active malicious repositories.
- GitHub has historically relied on manual reports for removal, failing to proactively identify or purge the automated distribution network.