TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Github scam investigation: Thousands of “mods” and “cracks” stealing data

388 pointsby timsh3 months ago

28 comments

klaas-3 months ago
I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam&#x2F;malware comments and links, but even internally their teams can&#x27;t reach anyone to get it fixed. Example <a href="https:&#x2F;&#x2F;feedback.azure.com&#x2F;d365community&#x2F;idea&#x2F;9d0b22d8-c025-ec11-b6e6-000d3a4f0f1c" rel="nofollow">https:&#x2F;&#x2F;feedback.azure.com&#x2F;d365community&#x2F;idea&#x2F;9d0b22d8-c025-...</a>
评论 #43204252 未加载
评论 #43205242 未加载
评论 #43204467 未加载
评论 #43205018 未加载
评论 #43204217 未加载
评论 #43205492 未加载
评论 #43205599 未加载
评论 #43207641 未加载
评论 #43204347 未加载
Aurornis3 months ago
These repos post to Discord webhooks to notify of newly compromised systems.<p>I’ve found Discord to be responsive to abuse complaints in the past. If someone wrote a simple script to download these repos and extract the Discord webhook links I bet you could get Discord to shut down their accounts.<p>In my past experience Discord was aggressive about this, going so far as to ban the accounts of people who had participated on those servers with clearly illegal purposes. They’ll come back and make new accounts again, of course, but having them lose all of their connected servers, history, and requiring them to update every single one of their malware drops should slow them down considerably.
评论 #43205781 未加载
评论 #43205933 未加载
评论 #43206208 未加载
评论 #43206175 未加载
vegadw3 months ago
I think to an extent Microsoft is the guilty party here. For may cracks Windows Defender will trip saying &quot;Win32&#x2F;Keygen&quot; even if there&#x27;s no actual malware <a href="https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;wdsi&#x2F;threats&#x2F;malware-encyclopedia-description?Name=HackTool:Win32&#x2F;Keygen" rel="nofollow">https:&#x2F;&#x2F;www.microsoft.com&#x2F;en-us&#x2F;wdsi&#x2F;threats&#x2F;malware-encyclo...</a><p>This trains people that do a lot of piracy to be used to turning off their antivirus to let something through, which is fine until it&#x27;s not. It&#x27;s like drugs, if we know a subset of the population will do them no matter what, we should make it safe for them to the extent we can. False positives, causing people to ignore actual positives, creates a market for these things.
评论 #43206128 未加载
评论 #43208298 未加载
dcow3 months ago
Why should malware repos be deleted?<p>Serious question. The repos aren&#x27;t themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
评论 #43205577 未加载
评论 #43204263 未加载
评论 #43204112 未加载
评论 #43204503 未加载
评论 #43205370 未加载
评论 #43204220 未加载
评论 #43203640 未加载
评论 #43203845 未加载
评论 #43204169 未加载
评论 #43204428 未加载
评论 #43204045 未加载
评论 #43205047 未加载
评论 #43205027 未加载
KomoD3 months ago
Fun fact: if you come across one of these discord webhooks you can delete them.<p>Just curl -X DELETE <a href="https:&#x2F;&#x2F;discord.com&#x2F;api&#x2F;webhooks&#x2F;" rel="nofollow">https:&#x2F;&#x2F;discord.com&#x2F;api&#x2F;webhooks&#x2F;</a>[...]
评论 #43204690 未加载
评论 #43206381 未加载
评论 #43205940 未加载
评论 #43206193 未加载
aerzen3 months ago
I think the core of problem here is that applications are not isolated on the OS level.<p>If I download and install a mod for minecraft, it should never have access to anything on my computer, except for the minecraft game files itself. If I open a spreadsheet in Excel, the excel process should have access only to that file and it&#x27;s own config files.<p>Something similar to how android works, were the app has to explicitly ask the user to access their files.
评论 #43204761 未加载
评论 #43209301 未加载
MaxGripe3 months ago
In my opinion, Microsoft’s entire support is at a tragically poor and hopeless level. GitHub is flooded with open issues that remain open for years without any response from Microsoft. The same applies to Azure. The technical support there is also truly terrible, and it’s easy to find horror stories online about people losing access to their accounts and being unable to restore them.
评论 #43204595 未加载
评论 #43309241 未加载
avodonosov3 months ago
Some time ago i was asked to help installing a mode for Plants vs. Zombies - a PVZ Fusion mode.<p>When searching for it I found multiple, some had download from github repos. None was looking trustworthy enough, so I didnt download any. But I hesitated a little.<p>From how they looked, I think now that was the kind of malware the author describes.
t_believ-er8733 months ago
If you&#x27;ve identified GitHub repositories hosting malware, you can report them directly to GitHub via their Abuse Report page, providing links and any relevant details. GitHub typically removes repositories that violate their Acceptable Use Policy, but response times may vary. If the malware is actively being used for harm, you may also consider reporting it to security organizations or CERT teams.
评论 #43204776 未加载
评论 #43205222 未加载
评论 #43205428 未加载
评论 #43204763 未加载
Fokamul3 months ago
Ooh, these types of malwares are very old.<p>Most fun you can have is to generate real-like looking data (there are tools for that) and mass send them to these discord webhooks.<p>;-)
评论 #43204033 未加载
Jimmc4143 months ago
What&#x27;s concerning is that this repository appears to be the template that much of this malware was built from: <a href="https:&#x2F;&#x2F;github.com&#x2F;Jalynn0922&#x2F;steal-cook">https:&#x2F;&#x2F;github.com&#x2F;Jalynn0922&#x2F;steal-cook</a>. This repo mentioned in the article has existed on GitHub for 3 years without being taken down.<p>Also, I am seeing firsthand that AI is not good at detecting this stuff. Claude&#x27;s main problem in a code review of one of its descendants was the unethical use of an aim-bot.<p>edit: to clarify, my concern is about how this can exist on Github for 3 years. Thank you for compiling this and sharing your review. Great work.
评论 #43206310 未加载
nottorp3 months ago
&quot;Or why you should never download game mods&quot;...<p>Like everything else, you shouldn&#x27;t blindly search on github - or any other download site.<p>Only download from links referred from the official site if there&#x27;s any, or the game&#x27;s forum, or any other trustable and human reviewed source.
评论 #43214653 未加载
extraduder_ire3 months ago
&gt; Less then 10% of them have open issues with complaints - others look just fine.<p>I don&#x27;t know why anyone running one of these schemes to distribute malware would even enable the issues tab on github, let alone not delete every issue posted containing keywords like malware, trojan, virus, etc. with a script.<p>Are hidden until approved issues not supported on github? Is this caused by some limitation of creating these repos programmatically?
评论 #43206269 未加载
Thorrez3 months ago
&gt;Yes, Redox creates and starts sqlite to gather all the data in a good-looking way.<p>Is that saying it creates a sqlite database? I kind of doubt it. I think more likely is it uses sqlite to read from existing sqlite databases that exist on disk, to steal data from them.
tomaytotomato3 months ago
I must admit, sometimes reading gists and other repos on fixing hardware issues I think, &quot;am I downloading malware?&quot;.<p>Better to have an attitude that Github is malware and a healthy skepticism of any repo?
avodonosov3 months ago
Just deleting them is not so useful. It would be better to uncover the people behind them and who use the collected data.<p>Some honeypot scheme or social engeneering against them.<p>Ideas?
neutralx3 months ago
First image in the article reminds me of draw.io diagrams. Is this a drawio theme&#x2F;library or some other tool was used to create it?
评论 #43204743 未加载
numba8882 months ago
The problem is this can be anything, not just mods and cracks. That&#x27;s why I keep separate laptop for banking. This may not help if hackers take over the router. But still better than nothing.
andypiper3 months ago
I&#x27;ve been reporting these repos forever, they just keep on coming.
miunau3 months ago
npm is full of this shit too, eg. <a href="https:&#x2F;&#x2F;www.npmjs.com&#x2F;package&#x2F;openssl-node" rel="nofollow">https:&#x2F;&#x2F;www.npmjs.com&#x2F;package&#x2F;openssl-node</a> which I reported weeks ago but is still sitting there.
Yeul3 months ago
I always thought it was amusing that if you ask about pirating Windows or Office you get a link to GitHub.<p>Microsoft is alright in my book. Let GitHub be free.
nisten3 months ago
No?<p>Maybe could stop people from being able to git pull them without a confirmation, but deleting does not make sense
jbverschoor3 months ago
Just don&#x27;t allow direct downloads or clones. It will solve a lot, although not many.
nomilk3 months ago
We could make an open source database. Then very simple browser extension to place a very prominent warning on any GitHub repo page that happens to be suspected malware.<p>I guess the problem is that only helps those who already know they need to watch out for this sort of thing, not the users most likely to be pwned.
评论 #43205931 未加载
nisten3 months ago
No
teddyh3 months ago
If there is no malware allowed on GitHub, I guess malware researchers have to use somewhere else to host their code. Which would be a preferable outcome, honestly.
linwangg3 months ago
This raises a big question: How effective is GitHub’s abuse reporting system against large-scale malware campaigns? If 1,000+ malicious repos can persist for months, does this mean GitHub lacks automated scanning or relies too much on user reports?
评论 #43206320 未加载
评论 #43205870 未加载
评论 #43206080 未加载
评论 #43206401 未加载
neuroelectron3 months ago
Is it really a problem to host malware on github?
评论 #43205993 未加载