{"id":833793,"date":"2025-03-13T14:14:26","date_gmt":"2025-03-13T19:14:26","guid":{"rendered":"https:\/\/newsycanuse.com\/index.php\/2025\/03\/13\/fake-github-projects-used-to-steal-crypto-kaspersky-warns\/"},"modified":"2025-03-13T14:14:26","modified_gmt":"2025-03-13T19:14:26","slug":"fake-github-projects-used-to-steal-crypto-kaspersky-warns","status":"publish","type":"post","link":"https:\/\/newsycanuse.com\/index.php\/2025\/03\/13\/fake-github-projects-used-to-steal-crypto-kaspersky-warns\/","title":{"rendered":"Fake GitHub Projects Used to Steal Crypto, Kaspersky Warns"},"content":{"rendered":"<p>Bitcoins <\/p>\n<div>\n<p><a href=\"https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns.jpg\" data-caption><img loading=\"lazy\" decoding=\"async\" width=\"696\" height=\"365\"   alt=\"bitcoins Fake GitHub Projects Used to Steal Crypto, Kaspersky Warns\" title=\"bitcoins Web_Fake-GitHub-Projects-Used-to_Steal-Crypto,-Kaspersky-Warns\" data-old-src=\"data:image\/svg+xml,%3Csvg%20xmlns='http:\/\/www.w3.org\/2000\/svg'%20viewBox='0%200%20696%20365'%3E%3C\/svg%3E\" srcset=\"https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns-696x365.jpg 696w, https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns-300x158.jpg 300w, https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns-1024x538.jpg 1024w, https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns-768x403.jpg 768w, https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns-800x420.jpg 800w, https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns-1068x561.jpg 1068w, https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns.jpg 1200w\" src=\"https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2025\/02\/Web_Fake-GitHub-Projects-Used-to_Steal-Crypto-Kaspersky-Warns-696x365.jpg\"><\/a><\/p>\n<h4><strong>Hackers are creating fake GitHub projects filled with malware to steal crypto. In November, at least one unlucky victim lost 5 bitcoins (worth around $442,000) after downloading a malicious project. Read on to learn more.<\/strong><\/h4>\n<p><span data-preserver-spaces=\"true\">The <a href=\"https:\/\/securelist.com\/gitvenom-campaign\/115694\/\" target=\"_blank\" rel=\"noopener\">research study<\/a> from Kaspersky describes fake project tactics used to steal crypto through deceptive software downloads.<\/span><\/p>\n<h5><strong>How Hackers Are Using Fake GitHub Projects to Steal Crypto<\/strong><\/h5>\n<p><span data-preserver-spaces=\"true\">GitHub is a leading platform for developers who wish to share and synchronize their coding efforts. Unfortunately, hackers are taking advantage of its open nature. Kaspersky analyst Georgy Kucherin explains that hackers create fake repositories under \u201c<a href=\"https:\/\/github.com\/r00t-3xp10it\/venom\" target=\"_blank\" rel=\"noopener\">GitVenom<\/a>.\u201d These projects pose legitimate tools but steal crypto and personal data.<\/span><\/p>\n<blockquote>\n<p dir=\"ltr\" lang=\"en\">???? ALERT: Hackers are making fake GitHub projects to steal crypto, according to Kaspersky.<\/p>\n<p>The hackers of the malware campaign called GitVenom have created hundreds of repositories on GitHub hosting fake projects that contain remote access trojans (RATs), info-stealers and\u2026 <a href=\"https:\/\/t.co\/NfZL6aWiKD\">pic.twitter.com\/NfZL6aWiKD<\/a><\/p>\n<p>\u2014 Cointelegraph (@Cointelegraph) <a href=\"https:\/\/twitter.com\/Cointelegraph\/status\/1894655038355587079?ref_src=twsrc%5Etfw\">February 26, 2025<\/a><\/p>\n<\/blockquote>\n<p><span data-preserver-spaces=\"true\">Some of the fake projects include:<\/span><\/p>\n<ul>\n<li><span data-preserver-spaces=\"true\">A Telegram bot that claims to manage Bitcoin wallets.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">A tool for automating Instagram account interactions.<\/span><\/li>\n<\/ul>\n<p><span data-preserver-spaces=\"true\">Hackers use AI, fake updates, and inflated commits to make projects look legitimate. Once downloaded, the malware inside these projects activates. It steals data and scans for crypto wallet addresses, replacing them with hacker-controlled ones.<\/span><\/p>\n<h5><strong>How the Malware Works<\/strong><\/h5>\n<p><span data-preserver-spaces=\"true\">Once a victim downloads and installs the fake project, the malware copies sensitive data, including:<\/span><\/p>\n<ul>\n<li><span data-preserver-spaces=\"true\">Saved credentials (passwords and logins).<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Crypto wallet information.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\"><span data-preserver-spaces=\"true\">Browsing history.<br \/>\n<\/span><\/span><\/p>\n<blockquote>\n<p dir=\"ltr\" lang=\"en\">GitHub users, be careful!<\/p>\n<p>GitVenom campaign uses fake projects to spread malware, stealing crypto and data. Verify repos before use: check code, READMEs, and commits; or stick to known, trusted repos.<\/p>\n<p>See more here: <a href=\"https:\/\/t.co\/Dq19Wjb9Yo\">https:\/\/t.co\/Dq19Wjb9Yo<\/a><\/p>\n<p>\u2014 Cosmos Rescue (@cosmosrescue) <a href=\"https:\/\/twitter.com\/cosmosrescue\/status\/1894653556864491662?ref_src=twsrc%5Etfw\">February 26, 2025<\/a><\/p>\n<\/blockquote>\n<\/li>\n<\/ul>\n<p><span data-preserver-spaces=\"true\">The stolen data gets to hackers through Telegram. A clipboard hijacker runs in the background, looking for crypto wallet addresses. If a user tries to copy and paste their wallet address, the malware swaps it with the hacker\u2019s address, redirecting funds to the attackers.<\/span><\/p>\n<h5><strong>Who Is at Risk?<\/strong><\/h5>\n<p><span data-preserver-spaces=\"true\">According to Kaspersky, the GitVenom campaign targets users worldwide. However, it focuses more on Russia, Brazil, and Turkey. The fact that <a href=\"https:\/\/www.altcoinbuzz.io\/?s=hackers\" target=\"_blank\" rel=\"noopener\">hackers<\/a> have been running this scheme for at least two years suggests it has effectively tricked victims.<\/span><\/p>\n<blockquote>\n<p dir=\"ltr\" lang=\"en\">GitHub Malware Alert \u26a0\ufe0f<\/p>\n<p>Our Global Research &#038; Analysis Team (GReAT) uncovered GitVenom\u2014a stealthy, multi-stage <a href=\"https:\/\/twitter.com\/hashtag\/malware?src=hash&#038;ref_src=twsrc%5Etfw\">#malware<\/a> campaign exploiting open-source code. Infected repositories targeted <a href=\"https:\/\/twitter.com\/hashtag\/gamers?src=hash&#038;ref_src=twsrc%5Etfw\">#gamers<\/a> and <a href=\"https:\/\/twitter.com\/hashtag\/crypto?src=hash&#038;ref_src=twsrc%5Etfw\">#crypto<\/a> investors, hijacking wallets and siphoning $485,000 in <a href=\"https:\/\/twitter.com\/hashtag\/Bitcoin?src=hash&#038;ref_src=twsrc%5Etfw\">#Bitcoin<\/a>.<\/p>\n<p>Get\u2026 <a href=\"https:\/\/t.co\/Ol7X7b1mwQ\">pic.twitter.com\/Ol7X7b1mwQ<\/a><\/p>\n<p>\u2014 Kaspersky (@kaspersky) <a href=\"https:\/\/twitter.com\/kaspersky\/status\/1894291124694426107?ref_src=twsrc%5Etfw\">February 25, 2025<\/a><\/p>\n<\/blockquote>\n<h5><strong>How to Stay Safe<\/strong><\/h5>\n<p><span data-preserver-spaces=\"true\">Hackers focus on <a href=\"https:\/\/www.altcoinbuzz.io\/?s=github\" target=\"_blank\" rel=\"noopener\">GitHub<\/a> because it has many developers. They will continue creating harmful projects. However, they will make minor strategic adjustments over time. Many steps exist to safeguard yourself against attacks:<\/span><\/p>\n<ul>\n<li><span data-preserver-spaces=\"true\">Check all unverified GitHub projects.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Always confirm the platform sending third-party code before starting any downloads.<\/span><\/li>\n<li><span data-preserver-spaces=\"true\">Before downloading, check the code\u2019s behavior to ensure it\u2019s malware-free.<\/span><\/li>\n<\/ul>\n<p><span data-preserver-spaces=\"true\">All files downloaded from the internet must undergo a security scan before regular execution.<\/span><\/p>\n<h5><strong>Conclusion<\/strong><\/h5>\n<p><span data-preserver-spaces=\"true\">Hackers\u2019 skill levels continue to advance, and they are using fake GitHub projects to steal crypto assets. Always stay alert while validating your download sources. Do not assume a secure appearance indicates project safety. Your crypto assets face more significant threats from theft, so a simple increase in caution will help defend them.<\/span><\/p>\n<p><img loading=\"lazy\" width=\"1197\" height=\"148\" decoding=\"async\" data-old-src=\"data:image\/svg+xml,%3Csvg%20xmlns='http:\/\/www.w3.org\/2000\/svg'%20viewBox='0%200%201197%20148'%3E%3C\/svg%3E\" src=\"https:\/\/www.altcoinbuzz.io\/wp-content\/uploads\/2023\/09\/Alpha_website_leaderboard-banner-1.jpg\"><\/p>\n<h6><strong>Disclaimer<\/strong><\/h6>\n<p>The information discussed by Altcoin Buzz is not financial advice. This is for educational, entertainment, and informational purposes only. Any information or strategies are thoughts and opinions relevant to the accepted levels of risk tolerance of the writer\/reviewers and their risk tolerance may be different than yours. We are not responsible for any losses that you may incur as a result of any investments directly or indirectly related to the information provided. Bitcoin and other cryptocurrencies are high-risk investments so please do your due diligence. Copyright Altcoin Buzz Pte Ltd.<\/p>\n<\/p><\/div>\n<p> Thomas Mongold <a href=\"https:\/\/www.altcoinbuzz.io\/bitcoin-and-crypto-guide\/fake-github-projects-used-to-steal-crypto-kaspersky-warns\/\" class=\"button purchase\" rel=\"nofollow noopener\" target=\"_blank\">Read More<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers are creating fake GitHub projects filled with malware to steal crypto. In November, at least one unlucky victim lost 5 bitcoins (worth around $442,000) after downloading a malicious project. Read on to learn more. The research study from Kaspersky describes fake project tactics used to steal crypto through deceptive software downloads. How Hackers Are<\/p>\n","protected":false},"author":1,"featured_media":833794,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[23298,2606],"tags":[11476],"class_list":{"0":"post-833793","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-github","8":"category-projects","9":"tag-bitcoins"},"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/833793","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/comments?post=833793"}],"version-history":[{"count":0,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/posts\/833793\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media\/833794"}],"wp:attachment":[{"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/media?parent=833793"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/categories?post=833793"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/newsycanuse.com\/index.php\/wp-json\/wp\/v2\/tags?post=833793"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}