BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Hackers Use 67+ Trojanized GitHub Repos to Spread Malware

Over 67 Trojanized Python Repositories Removed from GitHub in Widespread Malware Campaign Targeting Game Cheats and Crypto Wallets

  • Cybersecurity researchers identified a large-scale scheme involving over 67 trojanized Python tool repositories on GitHub.
  • The campaign targets users seeking account cleaning tools, game cheats, and other utilities by delivering malicious code instead of real software.
  • These threats can steal credentials, browser data, session tokens, and even inject Malware into cryptocurrency wallets.
  • GitHub has since removed all identified malicious repositories associated with this campaign.
  • The same tactics are linked to several groups spreading malware through techniques like fake popularity and cloned repositories.

Researchers have discovered that over 67 repositories on GitHub claimed to offer Python-based Hacking and utility tools, but instead delivered trojanized software designed to steal sensitive data. The campaign has been active since at least 2023 and targets individuals searching for account cleaners, game cheats, and similar applications.

- Advertisement -

The threat actor behind this activity, known as Banana Squad, used fake repositories that imitate legitimate ones. These repositories distributed programs with hidden malicious features, notably stealing information from Windows systems and injecting code into cryptocurrency wallet apps like Exodus. GitHub has removed all the affected repositories after these findings.

According to ReversingLabs, "Backdoors and trojanized code in publicly available source code repositories like GitHub are becoming more prevalent and represent a growing software supply chain attack vector." The company urged developers to verify that the code they use is trustworthy.

Other cybersecurity firms have reported similar tactics. Trend Micro recently uncovered 76 more malicious repositories tied to a group called Water Curse, which distributed multi-stage malware to steal passwords and browser data. Check Point detailed another active campaign using so-called Stargazers Ghost Network to spread Java-based malware targeting Minecraft users.

These strategies include boosting the visibility of malicious repositories through fake stars and frequent updates to appear as top results on GitHub searches. Sophos highlighted that some campaigns target amateur cybercriminals who seek easy-to-use malware, only to become victims themselves.

- Advertisement -

Researchers found more than 133 backdoored repositories in related campaigns, using various methods like Visual Studio PreBuild events, Python scripts, and browser-based files to deliver malware. Some of these efforts appear to be part of a distribution-as-a-service model, using multiple social platforms like Discord and YouTube to spread harmful links.

Sophos warned, "It remains unclear if this campaign is directly linked to some or all of the previous campaigns reported on, but the approach does seem to be popular and effective, and is likely to continue in one form or another."

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tether funds Drift hack victims in swap for USDT adoption

Tether will donate $127.5 million to help Solana-based exchange Drift Protocol recover $286 million...

Russia-linked crypto exchange Grinex shuts down after $13M hack

The sanctioned Russia-linked crypto exchange Grinex has halted operations after a major hack resulted...

Hayes: U.S.-Iran Conflict May Tank Bitcoin Before Liquidity Surge

Arthur Hayes described markets as being in a 'no trade zone' due to geopolitical...

Justin Sun decries “tyranny” in Trump-linked WLFI vote

World Liberty Financial proposed burning 4.5 billion WLFI tokens and restructuring vesting for 62...

Crypto Market-Maker Deal Disclosures Virtually Absent

Market-making arrangements are disclosed by fewer than 1% of crypto protocols, a rate dramatically...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading