TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

GitHub flooded with malware repos spoofing real projects–no response from GitHub

15 点作者 joshdotsmith3 个月前
GitHub is being overrun with repositories impersonating legitimate open-source projects to spread malware. One of them is spoofing my own app. I reported it through GitHub’s official channels days ago, reached out on social media, and even contacted individual GitHub employees. No response.<p>This isn’t just one or two cases; it looks like a massive campaign. The repos often copy a real project’s README and structure, though reworded through an LLM, but contain malicious code distributed through releases or sometimes attachments. Here’s one example: https:&#x2F;&#x2F;github.com&#x2F;ojas1103&#x2F;CircleProgressKit<p>Take care not to actually download this unless you know what you’re doing. This is malware.<p>Some of these have a high number of stars on occasion, though they are sometimes difficult to find because the Threat Actor appears to be constantly force pushing code to force GitHub to re-index it, so they have to be discovered through external indexes.<p>The malware seems to predominantly contain Redline infostealers. It appears that they may even include some of the recent more advanced 2FA credential stealers.<p>The worst part? These aren’t getting taken down despite multiple reports. GitHub appears to be a black hole. If someone downloads a spoofed repo thinking it’s safe, they could be running malware. I don’t know how many people have been affected, but it seems to be escalating.<p>At this point, I’m out of ideas. Has anyone else dealt with this? How do we get GitHub to take this seriously?

3 条评论

skydhash3 个月前
My suggestion (which I think I shared here for someone that was facing the same problem) is to go the way of bigger open source projects. Create a web site and add a link to the repo for the project. That&#x27;s how I search for official repos. Either mention from reputable sources, or the project&#x27;s web page. Not that it&#x27;s more trustful, but a bit harder to spoof than just create a new repo on GitHub.
yorwba3 个月前
I reported some issue spam in August last year and recently got an email from GitHub that they&#x27;re looking at it.<p>So your report might get looked at in half a year. Less if they have working filters to prioritize reported malware.
mindcrime3 个月前
&gt; At this point, I’m out of ideas. Has anyone else dealt with this? How do we get GitHub to take this seriously?<p>Not read any thriller &#x2F; conspiracy novels? :-) The way is to do exactly what you&#x27;re doing here: take the news public. Very public. The more the merrier. Post to HN, LinkedIn, Facebook, Slashdot, Twitter, TikTok, Reddit, etc. Send email to every news&#x2F;media outlet you can find contact info for. @mention people who work for CNN, MSNBC, ABC News, Fox News, CBS News, Reuters, Associated Press, etc. on Twitter, or find them on LinkedIn and message them. Write up a press release and submit using PRNewsWire and such-like. Record a video and post on Youtube. Contact the Attorneys General for all 50 US states. And so on.
评论 #43056187 未加载