Skip to content
← Back to newsCybercriminals Exploit GitHub to Steal Cryptocurrency Through Fake Projects
Security

Cybercriminals Exploit GitHub to Steal Cryptocurrency Through Fake Projects

By ToTo BugelmanNewcomer0 rep· 2/26/2025

In a disturbing trend, hackers are leveraging GitHub to create fake projects designed to steal cryptocurrency from unsuspecting users. This malicious campaign, dubbed "GitVenom" by cybersecurity firm Kaspersky, has reportedly led to significant financial losses, including the theft of 5 Bitcoin, valued at approximately $442,000.

 

Example of malicious repository structure: Securelist

 

Key Takeaways

  • Cybercriminals are creating fake GitHub repositories to distribute malware.

  • The campaign has been active for at least two years, targeting cryptocurrency users and gamers.

  • Victims are lured by seemingly legitimate projects that contain malicious code.

 

Overview of the GitVenom Campaign

Kaspersky's research indicates that the GitVenom campaign has seen hackers establish hundreds of fake repositories on GitHub. These repositories host various projects, including a Telegram bot for managing Bitcoin wallets and tools for automating social media interactions. The attackers have gone to great lengths to make these projects appear legitimate, employing well-designed documentation and artificially inflating the number of commits to create an illusion of active development.

 

Fragments of README.md pages with descriptions of fake projects

 

How the Attack Works

The malicious projects are designed to perform several harmful actions:

  1. Info Stealers: These components collect sensitive information such as saved credentials, cryptocurrency wallet data, and browsing history, which is then sent to the attackers via Telegram.

  2. Clipboard Hijackers: This malware monitors the clipboard for cryptocurrency wallet addresses and replaces them with addresses controlled by the hackers, redirecting funds to their wallets.

  3. Remote Access Trojans (RATs): Tools like AsyncRAT and Quasar RAT allow attackers to take control of infected devices, further compromising user security.

 

Victim Impact

The GitVenom campaign has reportedly resulted in at least one confirmed theft of 5 Bitcoin, highlighting the effectiveness of these malicious projects. The campaign has primarily targeted users in Russia, Brazil, and Turkey, but its reach is global, affecting cryptocurrency enthusiasts and developers worldwide.

 

Recommendations for Users

To protect against such threats, users are advised to:

  • Scrutinize Third-Party Code: Always review the actions performed by any third-party code before downloading or integrating it into projects.

  • Check Repository Authenticity: Look for signs of legitimacy, such as the number of stars, contributor accounts, and the age of the repository.

  • Use Security Software: Employ robust malware protection on all devices to detect and prevent infections.

 

Conclusion

As the GitVenom campaign demonstrates, the exploitation of trusted platforms like GitHub poses a significant risk to users. Cybercriminals will likely continue to adapt their tactics, making it essential for developers and cryptocurrency users to remain vigilant and informed about potential threats. By taking proactive measures, individuals can better safeguard their digital assets against these sophisticated attacks.

 

Sources

Discussion (0)

Sign in to join the discussion.

No comments yet. Be the first.

Cybercriminals Exploit GitHub to Steal Cryptocurrency Through Fake Projects | BlockzHub