🪙
292 fake GitHub repos spread infostealer malware targeting browsers and crypto wallets
🪙 Crypto

292 fake GitHub repos spread infostealer malware targeting browsers and crypto wallets

Cybersecurity firm ArcticWolf discovered 292 malicious GitHub repositories impersonating legitimate software tools, including security products, developer utilities and games. The embedded BoryptGrab infostealer stole data from 19 browsers, 32 crypto wallets, messaging apps, Steam and Windows Credential Manager, and uniquely bypassed Chrome's App-Bound Encryption. Russian actors are reportedly behind the campaign; most repos have been removed but some remain active.

Comments

No comments yet