{"id":4491,"date":"2025-06-07T10:03:52","date_gmt":"2025-06-07T10:03:52","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/06\/07\/hundreds-of-github-malware-repos-targeting-novice-cybercriminals-linked-to-single-user\/"},"modified":"2025-06-07T10:03:52","modified_gmt":"2025-06-07T10:03:52","slug":"hundreds-of-github-malware-repos-targeting-novice-cybercriminals-linked-to-single-user","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/06\/07\/hundreds-of-github-malware-repos-targeting-novice-cybercriminals-linked-to-single-user\/","title":{"rendered":"Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User"},"content":{"rendered":"<p>    Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated malware distribution campaign has weaponized over 140 GitHub repositories to target inexperienced cybercriminals and gaming cheat users, representing one of the largest documented cases of supply chain attacks on the platform.<\/p>\n<p>The repositories, masquerading as legitimate malware tools and game cheats, contain elaborate backdoors designed to infect users who compile the seemingly authentic code.<\/p>\n<p>The campaign centers around repositories linked to the email address ischhfd83@rambler.ru, with the oldest malicious commits dating back to November 2023.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhzKZ4wjX4xWaD-lP9GdRkPiacyqgY3hTI0xvyvMCRnYtijz4wbtY_SM4KlFQpKdsReHlPOGmFuUi3ApMdjLzxFO_wJrUtw3noZg5E9hU8QXKsqO5Gas8jpO4tigHqa6U22ubis5bP_wbH-vj24rlw2JOktZVSNuw6W8cMO5XcFevG_VxmsyAmRAYrxTZY\/s16000\/One%2520of%2520the%2520malicious%2520repositories%2520%28Source%2520-%2520Sophos%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">One of the malicious repositories (Source \u2013 Sophos)<\/figcaption><\/figure>\n<\/div>\n<p>Of the 141 discovered repositories, 133 contained backdoors utilizing four distinct infection methods, with the majority claiming to offer gaming cheats (58%) while others purport to be malware projects, exploits, or attack tools (24%).<\/p>\n<p>The remaining repositories focus on cryptocurrency tools, bot-related projects, and miscellaneous utilities.<\/p>\n<p>Sophos analysts <a href=\"https:\/\/news.sophos.com\/en-us\/2025\/06\/04\/the-strange-tale-of-ischhfd83-when-cybercriminals-eat-their-own\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the campaign after receiving a customer inquiry about \u201cSakura RAT,\u201d an open-source malware project that initially appeared to possess sophisticated anti-detection capabilities.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg7a_onwuDvLshCjBzgLFHz0Sz_tBeGcSgnRpCW-uFkyNchqiWsKnA-6hqmzIjeSR7ALg1fRnKFwOP-GgYNwyaTp1MsiDE4_okba0xjv2R7-S7lV0-LfwiMzqF2eqFkLwe2LdIy0qU9zJL5lwHR0i5aqtNE-vaGIDc2u80u7cMPIGIC_rJ9KvX1YTKgZ3I\/s16000\/A%2520post%2520on%2520a%2520cybercrime%2520forum%2520asking%2520for%2520help%2520with%2520Sakura%2520RAT%2520%28Source%2520-%2520Sophos%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">A post on a cybercrime forum asking for help with Sakura RAT (Source \u2013 Sophos)<\/figcaption><\/figure>\n<\/div>\n<p>Upon investigation, researchers discovered that while the RAT itself was non-functional due to empty forms and copied code from <a href=\"https:\/\/cybersecuritynews.com\/asyncrat-abusing-python-and-trycloudflare\/\" target=\"_blank\" rel=\"noreferrer noopener\">AsyncRAT<\/a>, it contained malicious PreBuild events designed to silently download malware onto users\u2019 devices during compilation.<\/p>\n<p>The scope and sophistication of this operation suggests a coordinated effort potentially linked to Distribution-as-a-Service operations previously reported in 2024-2025, though evidence indicates the campaign may have existed in various forms since 2022.<\/p>\n<p>The threat actor employs multiple deception techniques, including automated GitHub Actions workflows that create the illusion of active development through frequent commits, with some repositories accumulating nearly 60,000 commits despite being created only months earlier.<\/p>\n<h2 class=\"wp-block-heading\"><strong>The PreBuild Backdoor: A Multi-Stage Infection Chain<\/strong><\/h2>\n<p>The most prevalent backdoor variant, found in 111 repositories, exploits Visual Studio\u2019s PreBuild event functionality to execute malicious commands before project compilation.<\/p>\n<p>The attack begins when developers attempt to build seemingly legitimate Visual Basic projects, triggering a complex four-stage infection process hidden within the project\u2019s .vbproj file.<\/p>\n<p>The initial stage involves a heavily obfuscated batch command embedded in the PreBuild event field. This command creates a VBS script in the user\u2019s temporary directory containing three Base64-encoded strings.<\/p>\n<p>The script then concatenates these strings, decodes them, and writes the result to a PowerShell script before executing it with bypassed execution policies.<\/p>\n<p>The PowerShell payload implements a sophisticated decoding mechanism using a hardcoded key stored in the $prooc variable: \u201cUtCkt-h6=my1_zt\u201d.<\/p>\n<p>This script continuously loops through four functions that decode hardcoded URLs, fetch additional encoded content, and ultimately download a 7zip archive from <a href=\"https:\/\/cybersecuritynews.com\/github-mcp-server-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">GitHub<\/a>.<\/p>\n<p>The malware checks for existing 7zip installations and downloads the tool if necessary before extracting and executing a file called SearchFilter.exe.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEisz-bqG6iAYblitv_PrkCXS9Ok4PWCeegYb4u7Cot8oKdV005R5esIQO-w69d9g55urY1ywV-VyMRJUev7awI-wgIvnfFxMe4p6mFBKmYbi-e0WFZOXl20dASzjDCcIRVsZ3wYLAiSP5lOj3D26Cqv4z6C7elXERqRxgSBxevsmN5scqA87FWOyeOFuDM\/s16000\/The%2520initial%2520backdoor%2520%28Source%2520-%2520Sophos%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">The initial backdoor (Source \u2013 Sophos)<\/figcaption><\/figure>\n<\/div>\n<p>The initial <a href=\"https:\/\/cybersecuritynews.com\/new-stealthy-nodejs-backdoor-infects-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">backdoor<\/a> structure, showing how the threat actor uses HTML encoding and string obfuscation to disguise malicious batch commands.<\/p>\n<p>The final payload, delivered as a massive Electron application, contains over 17,000 lines of heavily obfuscated JavaScript code designed to disable <a href=\"https:\/\/cybersecuritynews.com\/windows-defender\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Defender<\/a>, delete shadow copies, and deploy multiple information stealers including AsyncRAT, Remcos, and Lumma Stealer.<\/p>\n<p>The campaign\u2019s persistence mechanisms include creating scheduled tasks with names mimicking legitimate Microsoft services and manipulating registry entries to exclude common analysis tools from antivirus scanning.<\/p>\n<p>The malware also establishes communication with threat actors through hardcoded <a href=\"https:\/\/cybersecuritynews.com\/hackers-use-google-forms-and-telegram-bots-to-collect-phished-credentials\/\" target=\"_blank\" rel=\"noreferrer noopener\">Telegram bot<\/a> tokens, automatically notifying operators of successful infections with basic system information including usernames, hostnames, and network configurations.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Speed up and enrich threat investigations with Threat Intelligence Lookup! -&gt;\u00a0<a href=\"https:\/\/intelligence.any.run\/plans?utm_source=csn_jun&amp;utm_medium=article&amp;utm_campaign=cyber-ti-guide-for-cisos&amp;utm_content=plans2&amp;utm_term=030625\" target=\"_blank\" rel=\"noreferrer noopener nofollow\"><strong>50 trial search requests<\/strong><\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hundreds-of-github-malware-repos-targeting-novice-cybercriminals\/\">Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hundreds-of-github-malware-repos-targeting-novice-cybercriminals\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hundreds of GitHub Malware Repos Targeting Novice Cybercriminals Linked to Single User A sophisticated malware distribution campaign has weaponized over 140 GitHub repositories to target inexperienced cybercriminals and gaming cheat users, representing one of the largest documented cases of supply chain attacks on the platform. The repositories, masquerading as legitimate malware tools and game cheats, [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-4491","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4491"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=4491"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/4491\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=4491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=4491"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=4491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}