#GitVenom
GitVenom恶意攻击利用GitHub数百仓库盗取加密货币的深度分析

https://qian.cx/posts/22169298-6070-4827-B7B3-4BB1ECF3E97F
October 10, 2025 at 4:41 PM
Código abierto: ¿aliado o enemigo? Los ciberdelincuentes están usando repositorios de #GitHub como cebo para ataques. 🎣🔓 #GitVenom es el último ejemplo de cómo el código compartido puede volverse en tu contra. bit.ly/3Rs1vXM
April 29, 2025 at 4:07 PM
Notícia da SecurityOnline

"Campanha GitVenom: Repositórios Maliciosos do GitHub Visam Cripto e Credenciais" #bolhasec
GitVenom Campaign: Malicious GitHub Repositories Target Crypto and Credentials
Uncover the GitVenom campaign targeting GitHub users with malicious repositories designed to steal credentials and cryptocurrency.
securityonline.info
March 29, 2025 at 9:30 PM
Cybercriminals behind GitVenom have already stolen 5 Bitcoins (worth $485,000). Most victims are in Brazil, Turkey, and Russia, but the campaign is global.

Stay safe: Always thoroughly check third-party code before running or integrating it into your projects.
March 21, 2025 at 12:00 AM
The campaign, dubbed "GitVenom," targets gamers and crypto investors, stealing personal data and hijacking Bitcoin wallets.

Kaspersky researchers found infected repositories masquerading as Instagram automation tools, Telegram bots for Bitcoin wallets, and game cracks.
March 21, 2025 at 12:00 AM
Attention gamers and crypto investors: Beware of malicious code on GitHub! Kaspersky uncovers "GitVenom" campaign stealing personal data and Bitcoin. Here's what you need to know 🚨

Hundreds of fake open-source projects on GitHub are infecting users with malware.
March 21, 2025 at 12:00 AM
GitVenom运动:假冒GitHub项目的网络攻击如何影响游戏玩家和加密投资者

https://qian.cx/posts/B17FD08E-67DF-481C-ADED-665B7A6ED166
March 20, 2025 at 6:14 AM
https://securelist.com/gitvenom-campaign/115694/
GitHubで公開されている偽のプロジェクトを通じて、情報窃取マルウェアが拡散されているというセキュリティに関する記事です。
攻撃者は、一見正当に見えるように偽装したプロジェクトを多数作成し、悪意のあるコードを埋め込んでいます。
感染すると、保存された認証情報や暗号通貨ウォレットのデータなどが窃取され、攻撃者に送信される可能性があります。
Fake GitHub projects distribute stealers in GitVenom campaign
Kaspersky researchers discovered GitVenom campaign distributing stealers and open-source backdoors via fake GitHub projects.
securelist.com
March 10, 2025 at 5:18 AM
<a href="https://securelist.com/gitvenom-campaign/115694/" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link" target="_blank" rel="noopener" data-link="bsky">securelist.com/gitv...
Fake GitHub projects distribute stealers in GitVenom campaign

- Git Venomキャンペーン、GitHub上の偽プロジェクトを利用した仮想通貨窃盗
- 偽プロジェクトは、Python, JavaScript, Cなど様々な言語で作成され、マルウェアを埋め込む
- 攻撃者は情報窃取、クリップボードハイジャック等を実施し、被害を拡大させた
Fake GitHub projects distribute stealers in GitVenom campaign
securelist.com
March 9, 2025 at 2:04 PM
https://www.kaspersky.com/about/press-releases/kaspersky-exposes-hidden-malware-on-github-stealing-personal-data-and-485000-in-bitcoin
Kasperskyの研究チームがGitHub上で個人情報とBitcoinを盗むマルウェアを発見しました。
GitVenomと呼ばれるこのキャンペーンは、ゲームユーザーや暗号資産投資家をターゲットにしています。
偽のプロジェクトに仕込まれたマルウェアにより、約485,000ドルのBitcoinが盗まれました。
Kaspersky exposes hidden malware on GitHub stealing personal data and $485,000 in Bitcoin
Kaspersky Global Research & Analysis Team (GReAT) discovered hundreds of open source repositories with multistaged malware targeting gamers and cryptoinvestors within a new campaign that was dubbed by Kaspersky as GitVenom. The infected projects include an automation instrument for interacting with Instagram accounts, a Telegram bot that enables the remote management of Bitcoin wallets and a crack tool to play the Valorant game. All of this alleged project functionality was fake, and cybercriminals behind the campaign stole personal and banking data and hijacked cryptowallet addresses from the clipboard. As a result of the malicious activity cybercriminals were able to steal 5 Bitcoins (around $485,000 at the time of investigation). Kaspersky detected the use of the infected repositories worldwide, with most cases in Brazil, Turkiye, and Russia.
www.kaspersky.com
March 4, 2025 at 9:02 AM
卡巴斯基在 GitHub 上发现隐藏的恶意程序

GitHub 上下载的软件并不意味着是安全的。俄罗斯安全公司卡巴斯基的安全团队披露了被称为 GitVenom 的行动,从数以百计的开源库中发现了针对游戏玩家和加密货币投资者的恶意程序。隐藏恶意程序的项目包括了 Instagram 自动化工具,远程管理比特币钱包的 Telegram 机器人程序,《无畏契约(VALORANT)》破解工具等等。恶意程序能窃取个人和银行数据,从剪切板劫持加密钱包地址。调查显示攻击者控制的钱包地址至今窃取了约 5 BTC,价值 48.5 万美元。大部分恶意程序感染发生在巴西、土耳其和俄罗斯。
March 3, 2025 at 11:02 AM
Hackers Use Fake GitHub Repositories to Steal Crypto in “GitVenom” Scam

Enjoyed this article? Share it with your friends! Kaspersky, a cybersecurity firm, reported that hackers are using fake GitHub repositories to steal cryptocurrency and login credentials. Kaspersky's investigation also revealed…
Hackers Use Fake GitHub Repositories to Steal Crypto in “GitVenom” Scam
Enjoyed this article? Share it with your friends! Kaspersky, a cybersecurity firm, reported that hackers are using fake GitHub repositories to steal cryptocurrency and login credentials. Kaspersky's investigation also revealed evidence that some of these repositories have been active for at least two years. The scam, known as "GitVenom", appears to have a higher concentration of victims in Russia, Brazil, and Turkey&hellip;
earlybirdsinvest.com
March 3, 2025 at 6:25 AM
The GitVenom campaign: cryptocurrency theft using GitHub

https://securelist.com/gitvenom-campaign/115694/
March 2, 2025 at 11:00 AM
The GitVenom campaign: cryptocurrency theft using GitHub
L: https://securelist.com/gitvenom-campaign/115694/
C: https://news.ycombinator.com/item?id=43182253
posted on 2025.02.26 at 04:42:58 (c=0, p=3)
March 2, 2025 at 9:28 AM
How to remove GitVenom GitVenom is a sophisticated malware campaign targeting gamers and cryptocu...

https://www.bugsfighter.com/remove-gitvenom/

#Trojans #Viruses

Event Attributes
How to remove GitVenom - BugsFighter
Effortlessly remove GitVenom malware with our step-by-step guide for a secure and clean system.
www.bugsfighter.com
March 1, 2025 at 2:14 PM
A new cyber threat, GitVenom, just siphoned $456K in Bitcoin using GitHub as its battlefield. Imagine the havoc this could wreak on a global scale… Fodder for my new thriller series. What real-world hacks keep you up at night? #CyberThriller #Hacking #CyberSecurity

thehackernews.com/2025/02/gitv...
GitVenom Malware Steals $456K in Bitcoin Using Fake GitHub Projects to Hijack Wallets
GitVenom malware on GitHub stole $456K in Bitcoin via fake projects, hijacking wallets and banking data.
thehackernews.com
February 28, 2025 at 1:50 PM
GitVenom Malware Steals $456K in Bitcoin Using Fake GitHub Projects to Hijack Wallets

https://cybersonar.org/go/Hw55Px
Posted at 11:13

#GitVenom
February 28, 2025 at 7:21 AM
📌 GitVenom malware campaign targets gamers and crypto investors via fake GitHub projects. Kaspersky researchers uncover hundreds of malicious repositories. #CyberSecurity #Malware https://tinyurl.com/2c4zg5ne
February 28, 2025 at 5:42 AM