Kaspersky Lab tell about fake projects on GitHub to steal cryptocurrencies
Hackers place malicious code to copy developers’ wallet data in files of supposedly legitimate projects
26.02.2025 - 12:25
1093
2 min
0
What’s new? According to a report from Kaspersky Lab, hackers are using GitHub to steal cryptocurrencies by creating fake software development projects and bots. The report warns users about the GitVenom campaign, which has been active for at least two years, which includes placing malicious code in individual projects on the popular platform among developers.
What else is known? The attack is carried out through the creation of fake projects in which hackers invite to join the development of Telegram-bots to manage bitcoin wallets or tools for computer games.
To create a semblance of legitimacy, such projects are accompanied by a README file, which can often be generated with the help of AI. In turn, the code of the supposedly real Python or JavaScript project itself is a Trojan virus.
If a developer downloads the malware, it launches a number of other exploit programs that collect passwords and crypto wallet data, as well as browsing history, combine them and send them to Telegram.
Remote access trojans such as AsyncRAT and Quasar take over the victim’s device, logging keystrokes, and taking screenshots.
Elliptic revealed details about the laundering of $1,46 billion stolen from Bybit
Analysts called the incident the largest single theft in history
Clipper-type programs that work with the clipboard change copied wallet addresses to those of the hackers, redirecting funds. As the lab’s analysts found out, one such wallet in November allowed hackers to earn 5 BTC, which at the time was valued at $485 000.
According to experts, the GitVenom campaign hit users from Russia, Brazil, and Turkey the hardest, although it operates worldwide.
Users were urged to scrutinize any code before running it, checking the authenticity of the project and README files or inconsistent commit histories.
Researchers believe these attacks will continue in the near future.
Useful material?
Incidents
Developers warned of potential risks to bridges across the ecosystem and asked exchanges for assistance.
Jun 22, 2026
Incidents
The defendant helped move funds stolen through investment scams and earned at least $4 million for his role in the operation.
Jun 10, 2026
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Telegram
Twitter