Fake GitHub Projects Used to Steal Crypto, Kaspersky Warns

Bitcoins

bitcoins Fake GitHub Projects Used to Steal Crypto, Kaspersky Warns

Hackers are creating fake GitHub projects filled with malware to steal crypto. In November, at least one unlucky victim lost 5 bitcoins (worth around $442,000) after downloading a malicious project. Read on to learn more.

The research study from Kaspersky describes fake project tactics used to steal crypto through deceptive software downloads.

How Hackers Are Using Fake GitHub Projects to Steal Crypto

GitHub is a leading platform for developers who wish to share and synchronize their coding efforts. Unfortunately, hackers are taking advantage of its open nature. Kaspersky analyst Georgy Kucherin explains that hackers create fake repositories under “GitVenom.” These projects pose legitimate tools but steal crypto and personal data.

???? ALERT: Hackers are making fake GitHub projects to steal crypto, according to Kaspersky.

The hackers of the malware campaign called GitVenom have created hundreds of repositories on GitHub hosting fake projects that contain remote access trojans (RATs), info-stealers and… pic.twitter.com/NfZL6aWiKD

— Cointelegraph (@Cointelegraph) February 26, 2025

Some of the fake projects include:

  • A Telegram bot that claims to manage Bitcoin wallets.
  • A tool for automating Instagram account interactions.

Hackers use AI, fake updates, and inflated commits to make projects look legitimate. Once downloaded, the malware inside these projects activates. It steals data and scans for crypto wallet addresses, replacing them with hacker-controlled ones.

How the Malware Works

Once a victim downloads and installs the fake project, the malware copies sensitive data, including:

  • Saved credentials (passwords and logins).
  • Crypto wallet information.
  • Browsing history.

    GitHub users, be careful!

    GitVenom campaign uses fake projects to spread malware, stealing crypto and data. Verify repos before use: check code, READMEs, and commits; or stick to known, trusted repos.

    See more here: https://t.co/Dq19Wjb9Yo

    — Cosmos Rescue (@cosmosrescue) February 26, 2025

The stolen data gets to hackers through Telegram. A clipboard hijacker runs in the background, looking for crypto wallet addresses. If a user tries to copy and paste their wallet address, the malware swaps it with the hacker’s address, redirecting funds to the attackers.

Who Is at Risk?

According to Kaspersky, the GitVenom campaign targets users worldwide. However, it focuses more on Russia, Brazil, and Turkey. The fact that hackers have been running this scheme for at least two years suggests it has effectively tricked victims.

GitHub Malware Alert ⚠️

Our Global Research & Analysis Team (GReAT) uncovered GitVenom—a stealthy, multi-stage #malware campaign exploiting open-source code. Infected repositories targeted #gamers and #crypto investors, hijacking wallets and siphoning $485,000 in #Bitcoin.

Get… pic.twitter.com/Ol7X7b1mwQ

— Kaspersky (@kaspersky) February 25, 2025

How to Stay Safe

Hackers focus on GitHub because it has many developers. They will continue creating harmful projects. However, they will make minor strategic adjustments over time. Many steps exist to safeguard yourself against attacks:

  • Check all unverified GitHub projects.
  • Always confirm the platform sending third-party code before starting any downloads.
  • Before downloading, check the code’s behavior to ensure it’s malware-free.

All files downloaded from the internet must undergo a security scan before regular execution.

Conclusion

Hackers’ skill levels continue to advance, and they are using fake GitHub projects to steal crypto assets. Always stay alert while validating your download sources. Do not assume a secure appearance indicates project safety. Your crypto assets face more significant threats from theft, so a simple increase in caution will help defend them.

Disclaimer

The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence. Copyright Altcoin Buzz Pte Ltd.

Thomas Mongold Read More

Latest

Rocket Lab wins $190 million Pentagon deal for hypersonic test flights

Rocket Lab launches HASTE for Hypersonix Feb. 27, 2926. Credit: Rocket Lab WASHINGTON — Rocket Lab, a provider of launch services and spacecraft, announced it won a $190 million Pentagon contract for 20 hypersonic test flights. The award, issued by the Pentagon’s Test Resource Management Center under its Multi-Service Advanced Capability Hypersonic Test Bed, or

US preparing for 2 week operation to take Strait of Hormuz: Kan News Israel

The United States is reportedly preparing to take control of the Strait of Hormuz, the critical shipping oil lane off Iran’s southeast coast, in a move that could extend the war. Israeli officials have detected American forces gathering, including the warship Tripoli, reports Israeli outlet Kan. An Israeli source told reporters the campaign could last

Chipotle Launches Fresh Cilantro Lime Sauce for a Limited Time Amid America’s Sauce Obsession

Made fresh daily with hand-chopped cilantro, lime, savory Mexican spices and hand-roasted jalapeños, Cilantro Lime Sauce delivers a bright kick of flavor with no artificial colors, flavors or preservatives. Fresh cilantro, lime and roasted jalapeños come together in a creamy new sauce made fresh daily Cilantro Lime Sauce is Chipotle’s highest-performing sauce in company test markets

Space Command classified wargame to include 25 commercial players

Military units from allied countries participate in Global Sentinel 2025 at Vandenberg Space Force Base, California, an annual exercise hosted by U.S. Space Command. Credit: U.S. Space Command This story was updated March 19. A previous version said the wargame would include 25 commercial firms. A U.S. Space Command spokesperson in an update said about

Newsletter

Don't miss

Rocket Lab wins $190 million Pentagon deal for hypersonic test flights

Rocket Lab launches HASTE for Hypersonix Feb. 27, 2926. Credit: Rocket Lab WASHINGTON — Rocket Lab, a provider of launch services and spacecraft, announced it won a $190 million Pentagon contract for 20 hypersonic test flights. The award, issued by the Pentagon’s Test Resource Management Center under its Multi-Service Advanced Capability Hypersonic Test Bed, or

US preparing for 2 week operation to take Strait of Hormuz: Kan News Israel

The United States is reportedly preparing to take control of the Strait of Hormuz, the critical shipping oil lane off Iran’s southeast coast, in a move that could extend the war. Israeli officials have detected American forces gathering, including the warship Tripoli, reports Israeli outlet Kan. An Israeli source told reporters the campaign could last

Chipotle Launches Fresh Cilantro Lime Sauce for a Limited Time Amid America’s Sauce Obsession

Made fresh daily with hand-chopped cilantro, lime, savory Mexican spices and hand-roasted jalapeños, Cilantro Lime Sauce delivers a bright kick of flavor with no artificial colors, flavors or preservatives. Fresh cilantro, lime and roasted jalapeños come together in a creamy new sauce made fresh daily Cilantro Lime Sauce is Chipotle’s highest-performing sauce in company test markets

Space Command classified wargame to include 25 commercial players

Military units from allied countries participate in Global Sentinel 2025 at Vandenberg Space Force Base, California, an annual exercise hosted by U.S. Space Command. Credit: U.S. Space Command This story was updated March 19. A previous version said the wargame would include 25 commercial firms. A U.S. Space Command spokesperson in an update said about

Hockey Hall of Fame gives Jack Hughes tough news on Olympic golden goal puck request

NEWYou can now listen to Fox News articles! If Jack Hughes wants to see the puck from the biggest goal of his life, he will have to travel to Toronto. The New Jersey Devils star and USA Hockey Olympic hero called out the Hockey Hall of Fame, saying it was "bulls---" it had the puck

Family Business? Tee Grizzley Reacts After His Mom Accuses Him Of Leaving Her To Struggle (PHOTOS)

Y’all… it looks like some family tension might be brewing behind the scenes involving Tee Grizzley and his mom. What seemed like a regular social media post quickly turned into something deeper. And now, folks are side-eyeing the situation and wondering what’s really going on. RELATED: Tee Grizzley Shares A Message For Artists After His

SoE necessary but not sufficient, business leaders say

PE­TER CHRISTO­PHER Se­nior Mul­ti­me­dia Re­porter pe­ter.christo­pher@guardian.co.tt Heavy hand­ed but nec­es­sary giv­en the state of crime in T&T. This was a com­mon as­sess­ment from var­i­ous busi­ness groups when asked for their per­spec­tive on the lat­est de­c­la­ra­tion of a state of emer­gency in the coun­try. The T&T Cham­ber of In­dus­try and Com­merce, in a re­leased is­sued yes­ter­day

The Big Business of Carolyn Bessette-Kennedy

Can a nine-episode limited series really impact an entire season of shopping trends? Today brands are experiencing—and chasing—the “Carolyn Bessette-Kennedy effect” as a result of Ryan Murphy’s Love Story. And in many cases, it’s more pervasive than they could have prepared for. The FX series, based on the relationship between John F. Kennedy Jr. and