GitHub faces widespread malware attacks affecting projects, including crypto

Major developer platform GitHub faced a widespread malware attack and reported 35,000 “code hits” on a day that saw thousands of Solana-based wallets drained for millions of dollars.

The widespread attack was highlighted by GitHub developer Stephen Lucy who first reported the incident earlier on Aug. 3. The developer came across the issue while reviewing a project he found on a Google search.

So far, various projects from crypto, Golang, Python, js, Bash, Docker and Kubernetes were found to be affected by the attack. The malware attack is targeted at the docker images, install docs and npm script, which is a convenient way to bundle common shell commands for a project.

To dupe developers and access critical data, the attacker first creates a fake repository (a repository contains all of the project’s files and each file’s revision history) and pushes clones of legit projects to GitHub. For example, the following two snapshots show this legit crypto miner project and its clone.

Original Crypto Mining Project Source: GithubCloned Crypto Mining Project Source: Github

Many of these clone repositories were pushed as “pull requests.” Pull requests let developers tell others about changes they have pushed to a branch in a repository on GitHub.

Related: Nomad reportedly ignored security vulnerability that led to $190M exploit

Once the developer falls prey to the malware attack, the entire environment variable (ENV) of the script, application, or laptop (electron apps), is sent to the attacker’s server. ENV includes security keys, AWS access keys, crypto keys and much more.

The developer has reported the issue to GitHub and advised developers to GPG sign their revisions made to the repository. GPG keys add an extra layer of security to your GitHub accounts and software projects by providing a way of verifying all revisions come from a trusted source

All Dutch and English crypto news!

Yuga Labs offloads 2 NFT games amid effort to ‘unshackle’ BAYC team

Yuga Labs has sold off the intellectual property rights of two of its games to Web3 gaming firm Faraway. News Own this piece of crypto history Collect this...

Worldcoin verwacht zomer 2024 lancering van World Chain op Ethereum

Worldcoin, opgericht door OpenAI CEO Sam Altman, heeft gisteren de lancering aangekondigd van World Chain. Dit nieuwe Ethereum Layer 2 (L2) netwerk is gebouwd op...

Former Ethereum dev Virgil Griffith asks for resentencing in North Korea case

Griffith’s attorneys are asking for a sentence reduction from 63 months to 51 months or less. News Own this piece of crypto history Collect this article as NFT Join...

Gary Gensler’s resignation ‘troll’ post disappoints Crypto X

SEC’s Gary Gensler managed to excite, then rudely disappoint crypto fans with a "legendary and respectable troll thread.” News Own this piece of crypto history Collect this article...

Beste exchanges

Koop je crypto bij Bitvavo