cognitive cybersecurity intelligence

News and Analysis

Search

Hundreds of GitHub repos served up malware for years

Kaspersky researchers discovered a long-running malware campaign targeting GitHub users. The threat actors created hundreds of fake repositories containing malicious code, which appeared genuine due to artificially inflated numbers of commit updates and well-designed README.md files. Unverified code downloaded malware from a separate attacker-controlled repository, which introduced several security threats. The highest numbers of infection attempts occurred in Russia, Brazil, and Turkey. The researchers warned against running or integrating third-party code without thoroughly checking it.

Source: www.helpnetsecurity.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts

Expanded BadBox botnet partly disrupted

The BadBox 2.0 malware botnet operation has been partially dismantled, affecting over 1 million Android devices worldwide. The joint operation, led by HUMAN’s Satori Threat