Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    List of Emmy nominees in top categories

    2026-2027 College Basketball Offseason Buzz: St. John’s Transfer Out For Season

    7/20: The Takeout with Major Garrett

    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest VKontakte
    Sg Latest NewsSg Latest News
    • Home
    • Politics
    • Business
    • Technology
    • Entertainment
    • Health
    • Sports
    Sg Latest NewsSg Latest News
    Home»Technology»Fake GitHub repositories exploit developer trust to spread malware
    Technology

    Fake GitHub repositories exploit developer trust to spread malware

    AdminBy AdminNo Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A campaign involving at least 292 impersonation repositories shows that securing the software supply chain requires developers to verify where tools, binaries, and source code originate. A threat actor created hundreds of fake GitHub organisations and repositories impersonating software companies, security vendors, developer tools, cryptocurrency services, and other technology brands.

    Arctic Wolf Labs identified at least 292 repositories linked to the campaign, which began on June 26. Seventy-eight associated redirectors remained active during its analysis, while GitHub had already removed a substantial portion of the identified infrastructure.

    The repositories copied branding, marketing material, and README content from legitimate software providers. They also included download buttons that directed visitors to attacker-controlled infrastructure.

    One repository impersonated Arctic Wolf through an organisation named “Arctic-Wolf-Security.” Its profile included a fabricated onboarding checklist and an “OFFICIAL PAGE” button linked to infrastructure controlled by the attacker.

    The campaign also used search engine optimisation to surface the repositories in software-related searches. The impersonated brands covered security tools, developer software, productivity applications, financial services, cryptocurrency wallets, email services, macOS utilities, and gaming products.

    Arctic Wolf said the operation did not exploit vulnerabilities in GitHub or the companies being impersonated. It relied on users downloading and running software from fraudulent repositories and linked websites.

    Shared download infrastructure

    Selecting a download link sent users through a GitHub Pages address before redirecting them to an external distribution domain. That domain displayed a page carrying the name of the brand represented in the original repository.

    The visible repositories and the downloaded archives were separate parts of the delivery chain. Arctic Wolf documented no build-provenance information linking the generated binaries to source code displayed in those repositories.

    SLSA defines provenance as verifiable information about where, when, and how a software artifact was produced. Such records can connect an artifact to its source and build process rather than relying on the appearance of the repository distributing it.

    The pages included labels such as “VirusTotal Approved,” “Secure Archive,” and “Verified Access.” These badges did not confirm that the files had been examined by those services.

    Arctic Wolf found that the attacker used a shared HTML and JavaScript template rather than building a separate page for each brand. The template extracted a brand name from the URL and inserted it into the page heading, subtitle, and browser title.

    The same template generated download pages for hundreds of impersonated brands. URL identifiers also allowed the operator to track which repository or redirector had produced a download.

    The server generated a new malicious ZIP archive approximately every 60 seconds. It changed the archive name and renamed the executable to match the software brand being impersonated.

    Arctic Wolf recovered two different malicious libcurl.dll samples and said their hashes should be treated as members of a rotating set. Because a changed file produces a different hash, one recovered hash would not identify later variants generated by the server.

    The archive examined by Arctic Wolf contained a legitimate, digitally signed WinGUP updater, a malicious libcurl.dll file, and additional files used to increase its size.

    The WinGUP executable was renamed to resemble the expected software installer. When opened, the legitimate program loaded the malicious DLL from the same directory through DLL side-loading.

    The signature applied to the legitimate WinGUP updater rather than every file included in the archive. Microsoft’s documented DLL search order includes the folder from which an application was loaded, and Arctic Wolf found that the updater loaded the malicious libcurl.dll placed beside it.

    The DLL decoded an embedded Windows payload and executed it in memory.

    Credential theft

    Arctic Wolf linked the payload to the BoryptGrab information-stealer family after comparing it with a previously documented sample. Its analysis found that 94% of the functions in the campaign’s sample were also present in the reference binary.

    The malware contained 11 theft modules targeting browser credentials, cookies, messaging applications, gaming accounts, Windows Credential Manager, cryptocurrency wallets, and files stored in Desktop and Documents folders.

    It also captured screenshots and collected information about the affected Windows system.

    The browser component included a method for accessing credentials protected by Chrome’s App-Bound Encryption. It launched supported browsers and injected code into their processes to obtain protected data.

    Collected information was placed in a ZIP archive and sent to a hardcoded command-and-control server hosted at an IP address in Russia.

    Arctic Wolf assessed the campaign as financially motivated but did not attribute it to a named threat group. Russian-language comments found in the download-page code were not considered sufficient to identify the operator.

    Verifying repository provenance

    The campaign relied on users treating a professional-looking GitHub repository as evidence that the software came from its stated publisher. Copied branding, documentation, organisation names, and download interfaces gave the repositories the appearance of official software sources.

    Reviewing source code alone would not confirm who controlled the repository or whether an externally hosted executable was built from the displayed code. Repository ownership and the provenance of a downloadable binary require separate verification.

    Repository activity can provide context but does not independently verify ownership. Organisation names, README files, branding, and polished documentation can be copied or generated by an impersonator.

    A GitHub-hosted page is also not proof that a download remains within GitHub. The campaign used github.io addresses as an intermediate step before redirecting users to external infrastructure controlled by the attacker.

    Developers can compare an account’s age, organisation identity, external destinations, and links from a vendor’s official website before cloning a repository or downloading software. A link embedded in a README file should be checked against its final destination rather than trusted because it begins on a GitHub-hosted page.

    Where available, signed releases and provenance attestations can provide stronger evidence about an artifact’s source and build process. These controls apply to the artifact they verify and do not establish the integrity of unrelated files packaged in the same archive.

    Arctic Wolf’s investigation showed that repository appearance, GitHub hosting, and a signed legitimate executable did not establish the trustworthiness of the complete download chain. The malicious archive combined those signals with an external redirect and an unsigned attacker-controlled DLL.

    Organisations can use private or internal registries to manage approved package dependencies. GitHub allows Dependabot to access private registries and, for some ecosystems, to operate without calls to public registries.

    Those controls address package resolution rather than standalone executables downloaded from repository links. Separate policies are required for unverified binaries, including review of their source, publisher, distribution channel, and available provenance information.

    Arctic Wolf advised defenders to monitor for the WinGUP updater loading libcurl.dll through the side-loading chain documented in the campaign. It also recommended rotating credentials, browser sessions, authentication tokens, and cryptocurrency wallet keys on systems that executed the malware.

    (Photo by Xavier Cee)

    See also: Four AsyncAPI npm packages carry Miasma botnet loader

    Want to dive deeper into the tools and frameworks shaping modern development? Check out the AI & Big Data Expo, taking place in Amsterdam, California, and London. Explore cutting-edge sessions on machine learning, data pipelines, and next-gen AI applications. The event is part of TechEx and co-located with other leading technology events. Click here for more information.

    Developer Tech News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Admin
    • Website

    Related Posts

    Excel and AI to get ‘tighter and tighter.’ Here’s what that means

    Singapore Investors Have A Final Opportunity To Own At Chelsea Residences By DAMAC In Dubai

    Jackaroo King Teams Up With UAE Animated IP Freej For A Middle East-Themed Social Adventure

    OPM moves to implement long-awaited retirement fix for federal first responders

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Most Impressive Team Streaks Of The 21st Century: Where Does 2024-26 Spain Rank?

    NBC’s ‘Stumble’ is a mockumentary about a cheer team with plenty of tumbling runs and heart

    Xiaomi shares post worst week in 3½ years as accidents stoke EV safety concerns

    Judge reverses Trump administration’s cuts of billions of dollars to Harvard University

    Top Reviews
    9.1

    Review: Mi 10 Mobile with Qualcomm Snapdragon 870 Mobile Platform

    By Admin
    8.9

    Comparison of Mobile Phone Providers: 4G Connectivity & Speed

    By Admin
    8.9

    Which LED Lights for Nail Salon Safe? Comparison of Major Brands

    By Admin
    Sg Latest News
    Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
    • Get In Touch
    © 2026 SglatestNews. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.