GitHub – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Thu, 24 Jul 2025 15:13:13 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 GitHub – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Hackers breach Toptal GitHub account, publish malicious npm packages https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/ https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/#respond Thu, 24 Jul 2025 15:13:12 +0000 https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/

NPM

Hackers compromised Toptal’s GitHub organization account and used their access to publish ten malicious packages on the Node Package Manager (NPM) index.

The packages included data-stealing code that collected GitHub authentication tokens and then wiped the victims’ systems.

Toptal is a freelance talent marketplace that connects companies with software developers, designers, and finance experts. The company also maintains internal developer tools and design systems, most notably Picasso, which they make available through GitHub and NPM.

Attackers hijacked Toptal’s GitHub organization on July 20, and almost immediately made public all 73 of the repositories available, exposing private projects and source code.

Tweet

In the days that followed, the attackers modified the source code of Picasso on GitHub to include malware and published 10 malicious packages on NPM as Toptal, making them appear as legitimate updates.

The malicious packages and modified versions are:

  • @toptal/picasso-tailwind (v3.1.0)
  • @toptal/picasso-charts (v59.1.4)
  • @toptal/picasso-shared (v15.1.0)
  • @toptal/picasso-provider (v5.1.1)
  • @toptal/picasso-select (v4.2.2)
  • @toptal/picasso-quote (v2.1.7)
  • @toptal/picasso-forms (v73.3.2)
  • @xene/core (v0.4.1)
  • @toptal/picasso-utils (v3.2.0)
  • @toptal/picasso-typography (v4.1.4)

The malicious packages were downloaded roughly 5,000 times before being detected, likely infecting developers with malware.

The hackers injected the malicious code into ‘package.json’ files to add two functions: steal data (‘preinstall’ script) and wipe hosts (‘postinstall’ script).

The first extracts the victim’s CLI authentication token and sends it to an attacker-controlled webhook URL, granting them unauthorized access to the target’s GitHub account.

After exfiltrating the data, the second script attempts to delete the entire filesystem with ‘sudo rm -rf –no-preserve-root /’ on Linux systems, or recursively and silently delete files on Windows.

According to code security platform Socket, Toptal deprecated the malicious packages on July 23 and reverted to safe versions, but issued no public statement to alert users who had downloaded the malicious releases to the risks.

Although the initial compromise method remains unknown, Socket lists multiple possibilities ranging from insider threats to phishing attacks targeting Toptal developers.

BleepingComputer has contacted Toptal for a statement, but we are still waiting for their response.

If you have installed any of the malicious packages, you are advised to revert to a previous stable version as soon as possible.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/feed/ 0 49418
Intel announces end of Clear Linux OS project, archives GitHub repos https://earlybirdsinvest.com/intel-announces-end-of-clear-linux-os-project-archives-github-repos/ https://earlybirdsinvest.com/intel-announces-end-of-clear-linux-os-project-archives-github-repos/#respond Mon, 21 Jul 2025 22:46:41 +0000 https://earlybirdsinvest.com/intel-announces-end-of-clear-linux-os-project-archives-github-repos/

Intel

The Clear Linux OS team has announced the shutdown of the project, marking the end of its 10-year existence in the open-source ecosystem.

Clear Linux is a Linux distribution developed and maintained by Intel, featuring aggressive optimizations for Intel hardware. Binaries are compiled using tuning flags designed explicitly for Intel CPUs.

It was a minimalist, modular OS that utilized software bundles for faster app installation and automatic performance tuning for optimal speed and power efficiency.

The distribution was primarily aimed at software developers, performance enthusiasts, and those working in cloud or server environments.

In an announcement to the Clear Linux forums, the team says the project will no longer receive security patches or any other updates. Therefore, its user base should migrate to other distributions for safety.

“Effective immediately, Intel will no longer provide security patches, updates, or maintenance for Clear Linux OS, and the Clear Linux OS GitHub repository will be archived in read-only mode,” reads the announcement.

“So, if you’re currently using Clear Linux OS, we strongly recommend planning your migration to another actively maintained Linux distribution as soon as possible to ensure ongoing security and stability.”

Although Intel has not officially explained why it’s shutting down the project, it could be due to low user adoption coupled with a high maintenance burden.

Considering that Clear Linux OS relied on its own package management and update system, as it is not a fork of another distribution, it required substantial engineering resources to provide user support.

Another key point may be Intel’s ongoing efforts to consolidate and tighten its operations, scaling back niche internal projects that don’t provide strategic value, and focusing more on new targets, such as agentic AI.

Although Clear Linux OS is now abandoned, the team behind it says it will remain invested in the Linux ecosystem and continue to provide Intel hardware optimizations that can be applied to other distributions and open-source software.

If you rely on Clear Linux OS, you are recommended to migrate to another distribution as soon as possible, as the lack of updates means the system will become vulnerable to flaws with known/public exploits in a short time.

Wiz

CISOs know that getting board buy-in starts with a clear, strategic view of how cloud security drives business value.

This free, editable board report deck helps security leaders present risk, impact, and priorities in clear business terms. Turn security updates into meaningful conversations and faster decision-making in the boardroom.

]]>
https://earlybirdsinvest.com/intel-announces-end-of-clear-linux-os-project-archives-github-repos/feed/ 0 48944
Fake “Security Alert” issues on GitHub use OAuth app to hijack accounts https://earlybirdsinvest.com/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/ https://earlybirdsinvest.com/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/#respond Mon, 17 Mar 2025 11:50:35 +0000 https://earlybirdsinvest.com/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/

GitHub

A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake “Security Alert” issues, tricking developers into authorizing a malicious OAuth app that grants attackers full control over their accounts and code.

“Security Alert: Unusual Access Attempt We have detected a login attempt on your GitHub account that appears to be from a new location or device,” reads the GitHub phishing issue.

All of the GitHub phishing issues contain the same text, warning users that their was unusual activity on their account from Reykjavik, Iceland, and the 53.253.117.8 IP address.

Fake
Fake “Security Alert” issue posted to GitHub repositories
Source: BleepingComputer

Cybersecurity researcher Luc4m first spotted the fake security alert, which warned GitHub users that their account was breached and that they should update their password, review and manage active sessions, and enable two-factor authentication to secure their accounts.

However, all of the links for these recommended actions lead to a GitHub authorization page for a “gitsecurityapp” OAuth app that requests a lot of very risky permissions (scopes) and would allow an attacker full access to a user’s account and repositories.

 

Permissions requested by malicious OAuth app
Permissions requested by malicious OAuth app
Source: BleepingComputer

The requested permissions and the access they provide are listed below:

  • repo: Grants full access to public and private repositories
  • user: Ability to read and write to the user profile
  • read:org: Read organization membership, organization projects, and team membership
  • read: discussion, write:discussion: Read and write access to discussions
  • gist: Access to GitHub gists
  • delete_repo: Permission to delete repositories
  • workflows, workflow, write:workflow, read:workflow, update:workflow: Control over GitHub Actions workflows

If a GitHub user logs in and authorizes the malicious OAuth app, an access token will generated and sent back to the app’s callback address, which in this campaign has been various web pages hosted on onrender.com (Render).

OAuth authorization link with a callback to an onrender.com page
OAuth authorization link with a callback to an onrender.com page
Source: BleepingComputer

The phishing campaign started this morning at 6:52 AM ET and is ongoing, with almost 12,000 repositories targeted in the attack. However, the number fluctuates, indicating that GitHub is likely responding to the attack.

Fake security alert issues created in GitHub repositories
Fake security alert issues created in GitHub repositories
Source: BleepingComputer

If you were impacted by this phishing attack and mistakenly gave authorization to the malicious OAuth app, you should immediately revoke its access by going into the GitHub Settings and then Applications.

From the Applications screen, revoke access to any GitHub Apps or OAuth apps that are unfamiliar or suspicious. In this campaign, you should look for apps named similarly to ‘gitsecurityapp.’

You should then look for new or unexpected GitHub Actions (Workflows) and whether private gists were created. 

Finally, rotate your credentials and authorization tokens.

BleepingComputer contacted GitHub about the phishing campaign and will udpate this story when we get a response.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/fake-security-alert-issues-on-github-use-oauth-app-to-hijack-accounts/feed/ 0 25641
Hackers Use Fake GitHub Repositories to Steal Crypto in “GitVenom” Scam https://earlybirdsinvest.com/hackers-use-fake-github-repositories-to-steal-crypto-in-gitvenom-scam/ https://earlybirdsinvest.com/hackers-use-fake-github-repositories-to-steal-crypto-in-gitvenom-scam/#respond Mon, 03 Mar 2025 06:25:04 +0000 https://earlybirdsinvest.com/hackers-use-fake-github-repositories-to-steal-crypto-in-gitvenom-scam/

Kaspersky, a cybersecurity firm, reported that hackers are using fake GitHub repositories to steal cryptocurrency and login credentials.

Kaspersky’s investigation also revealed evidence that some of these repositories have been active for at least two years. The scam, known as “GitVenom“, appears to have a higher concentration of victims in Russia, Brazil, and Turkey, though it has been observed worldwide.

Kaspersky researcher Georgy Kucherin revealed in a February 24 report that these fraudulent repositories pretend to offer useful tools, such as a Telegram bot for managing Bitcoin
BTC


$93,039.77

wallets or an Instagram automation tool. However, instead of functioning as described, they install malware that grants attackers access to sensitive information.

What is Chainlink? LINK Explained Simply (ANIMATED)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Hackers included detailed descriptions and instructional files, which Kaspersky suspects may have been generated with artificial intelligence (AI). They also manipulated project activity by continuously updating a timestamp file, which made it look like the repository was actively maintained.

Kaspersky found that the advertised features were non-functional, and the files executed meaningless actions while running hidden malware in the background. Once installed, the malware extracted saved credentials, browsing history, and cryptocurrency wallet details, sending them to attackers through Telegram.

Another malicious component worked as a clipboard hijacker, which monitored copied wallet addresses and replaced them with the hacker’s own. This method allowed attackers to intercept cryptocurrency transactions without the victim noticing.

On February 5, Kaspersky researchers discovered malware hidden in app development tools used to create apps for Google Play and the Apple App Store. What damage could it cause? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/hackers-use-fake-github-repositories-to-steal-crypto-in-gitvenom-scam/feed/ 0 22964
Crypto Scam Alert: Hackers Use GitHub To Steal Funds—Kaspersky https://earlybirdsinvest.com/crypto-scam-alert-hackers-use-github-to-steal-funds-kaspersky/ https://earlybirdsinvest.com/crypto-scam-alert-hackers-use-github-to-steal-funds-kaspersky/#respond Thu, 27 Feb 2025 05:53:01 +0000 https://earlybirdsinvest.com/crypto-scam-alert-hackers-use-github-to-steal-funds-kaspersky/

Cybercriminals have initiated a sophisticated attack that targets GitHub users. They are utilizing fake repositories to disseminate malware that steals personal data and cryptocurrency. Kaspersky, a security firm, has identified more than 200 repositories that deceive unsuspecting developers and merchants by posing as legitimate open-source projects.

Deceptive Repositories Inundate GitHub

The perpetrators of this scheme have designed their repositories to look credible, often depicting them as solutions for automating Instagram interactions or managing Bitcoin wallets. These bogus projects aim to convince consumers of their authenticity by employing professional descriptions, regular updates, and meticulously produced documentation.

Victims who fall to the trap install malware from these fraudulent repositories. Infected files contain remote access trojans (RATs), clipboard hijackers, and data-extracting software, allowing attackers to retrieve browser histories, cryptocurrency wallet details, and login credentials.

Malware Sends Stolen Data Via Telegram

When installed, the malware sends away the captured data to hackers through Telegram. Attackers use this secured messaging app to obtain sensitive information while remaining undetectable. In some cases, the malware alters clipboard information, which causes cryptocurrency transactions to be redirected to wallets controlled by the hackers.

The magnitude of the operation is a cause for concern. According to Kaspersky, one user lost 5 Bitcoins, valued at approximately $442,000, as a result of the hack. Kaspersky has monitored numerous incidents from different countries: Russia, Brazil, and Turkey are the most severely affected.

BTCUSD trading at $87,721 on the daily chart: TradingView.com

The GitVenom

In a February 24 report, Kaspersky analyst Georgy Kucherin stated that hackers had created hundreds of repositories on GitHub containing fictitious projects that contain remote access trojans (RATs), info-stealers, and clipboard hijackers as part of the malware operation, which the company named “GitVenom.”

Kucherin added the malware creators made a huge effort to make the projects look legitimate by including well-designed instruction files that were possibly generated with the use of artificial intelligence programs.

Extreme Caution A Must

Kaspersky urged users to “be extra cautious about downloading code from GitHub.” If you wish to reduce the possibility of becoming a victim of such attacks, maximum security measure is essential. This may involve scanning downloaded files for viruses, avoiding repositories with low activity or recent creation dates, and reviewing and verifying the history of repository owners.

As new cyber threats arise, users need to be alert in protecting their valuables. Modern social engineering and phishing techniques are sophisticated enough to outwit even the most experienced of programmers. To reduce the chance of potential threats in the future, it is ideal to remain cognizant and maintain rigorous security protocols.

Featured image from Gemini Imagen, chart from TradingView

]]>
https://earlybirdsinvest.com/crypto-scam-alert-hackers-use-github-to-steal-funds-kaspersky/feed/ 0 22142
Malicious GitHub repositories deploying hidden attacks on crypto wallets https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/ https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/#respond Wed, 26 Feb 2025 12:14:12 +0000 https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/

Kaspersky researchers have identified an attack vector on GitHub that uses repositories to distribute code that targets crypto wallets.

The investigation revealed a campaign dubbed GitVenom, in which threat actors created hundreds of GitHub repositories purporting to offer utilities for social media automation, wallet management, and even gaming enhancements.

Although these repositories were designed to resemble legitimate open-source projects, their code failed to deliver the advertised functions. Instead, it embedded instructions to install cryptographic libraries, download additional payloads, and execute hidden scripts.

GitVenom repos

The malicious code appears across Python, JavaScript, C, C++, and C# projects. In Python-based repositories, a lengthy sequence of tab characters precedes commands that install packages like cryptography and fernet, ultimately decrypting and running an encrypted payload.

JavaScript projects incorporate a function that decodes a Base64-encoded script, triggering the malicious routine.

Similarly, in projects using C, C++, and C#, a concealed batch script within Visual Studio project files activates at build time. Per Kaspersky’s report, each payload is configured to fetch further components from an attacker-controlled GitHub repository.

These additional components include a Node.js stealer that collects saved credentials, digital wallet data, and browsing history before packaging the information into an archive for exfiltration via Telegram.

Open-source tools such as the AsyncRAT implant and the Quasar backdoor are also used to facilitate remote access. A clipboard hijacker that scans for crypto wallet addresses and replaces them with those controlled by the attackers is also used. 

Attack vector is not new

The campaign, which has been active for several years with some repositories originating two years ago, has triggered infection attempts worldwide. Telemetry data indicate that attempts linked to GitVenom have been most prominent in Russia, Brazil, and Turkey.

Kaspersky researchers stressed the importance of scrutinizing third-party code before execution, noting that open-source platforms, while essential to collaborative development, can also serve as conduits for malware when repositories are manipulated to mimic authentic projects.

Developers are advised to double-check the contents and activity of GitHub repositories before integrating code into their projects.

The report outlines that these projects use AI to artificially inflate commit histories and craft detailed README files. Thus, when reviewing a new repo, developers should check for overly verbose language, formulaic structure, and even leftover AI instructions or responses in these areas.

While using AI to help craft a README file is not a red flag in itself, identifying it should spur developers to investigate further before using the code. Looking for community engagement, reviews, and other projects using the repo may aid with this. However, fake AI-generated reviews and social media posts also make this a tough challenge.

Blocscale
]]>
https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/feed/ 0 21983
Hackers Are Using Fake GitHub Code to Steal Your Bitcoin: Kaspersky https://earlybirdsinvest.com/hackers-are-using-fake-github-code-to-steal-your-bitcoin-kaspersky/ https://earlybirdsinvest.com/hackers-are-using-fake-github-code-to-steal-your-bitcoin-kaspersky/#respond Wed, 26 Feb 2025 07:15:43 +0000 https://earlybirdsinvest.com/hackers-are-using-fake-github-code-to-steal-your-bitcoin-kaspersky/

The GitHub code you use to build a trendy application or patch existing bugs might just be used to steal your bitcoin (BTC) or other crypto holdings, according to a Kaspersky report.

GitHub is popular tool among developers of all types, but even more so among crypto-focused projects, where a simple application may generate millions of dollars in revenue.

The report warned users of a “GitVenom” campaign that’s been active for at least two years but is steadily on the rise, involving planting malicious code in fake projects on the popular code repository platform.

The attack starts with seemingly legitimate GitHub projects — like making Telegram bots for managing bitcoin wallets or tools for computer games.

Each comes with a polished README file, often AI-generated, to build trust. But the code itself is a Trojan horse: For Python-based projects, attackers hide nefarious script after a bizarre string of 2,000 tabs, which decrypts and executes a malicious payload.

For JavaScript, a rogue function is embedded in the main file, triggering the launch attack. Once activated, the malware pulls additional tools from a separate hacker-controlled GitHub repository.

(A tab organizes code, making it readable by aligning lines. The payload is the core part of a program that does the actual work — or harm, in malware’s case.)

Once the system is infected, various other programs kick in to execute the exploit. A Node.js stealer harvests passwords, crypto wallet details, and browsing history, then bundles and sends them via Telegram. Remote access trojans like AsyncRAT and Quasar take over the victim’s device, logging keystrokes and capturing screenshots.

A “clipper” also swaps copied wallet addresses with the hackers’ own, redirecting funds. One such wallet netted 5 BTC — worth $485,000 at the time — in November alone.

Active for at least two years, GitVenom has hit users hardest in Russia, Brazil, and Turkey, though its reach is global, per Kaspersky.

The attackers keep it stealthy by mimicking active development and varying their coding tactics to evade antivirus software.

How can users protect themselves? By scrutinizing any code before running it, verifying the project’s authenticity, and being suspicious of overly polished READMEs or inconsistent commit histories.

Because researchers don’t expect these attacks to stop anytime soon: “We expect these attempts to continue in the future, possibly with small changes in the TTPs,” Kaspersky concluded in its post.

]]>
https://earlybirdsinvest.com/hackers-are-using-fake-github-code-to-steal-your-bitcoin-kaspersky/feed/ 0 21938
Zashi on GitHub & F-Droid: More Ways to Download https://earlybirdsinvest.com/zashi-on-github-f-droid-more-ways-to-download/ https://earlybirdsinvest.com/zashi-on-github-f-droid-more-ways-to-download/#respond Fri, 21 Feb 2025 04:20:46 +0000 https://earlybirdsinvest.com/zashi-on-github-f-droid-more-ways-to-download/

Android users will be able to bypass Google by downloading Zashi from F-Droid or GitHub! Zcash offers financial privacy and sovereignty, and we want to ensure that Zashi upholds those values, giving users greater control over how and where they access the app. 

  • Zashi for Android is available on GitHub.
  • Zashi for Android has been submitted to F-Droid and is pending approval.

Why F-Droid?

F-Droid is an independent app store that prioritizes open-source, privacy-respecting software. Unlike traditional app stores, it does not track or profile users, and it allows for completely anonymous downloads. By releasing Zashi on F-Droid, we are giving Zcashers more control over their digital footprint, ensuring they can use their wallet without unnecessary data collection, and without being subject to centralized app store control.

  • Privacy First – No tracking and no unnecessary data collection.
  • Transparent & Open-Source – F-Droid only allows fully open-source apps, ensuring community oversight.
  • Alternative App Distribution – Android users can install and update Zashi without depending on a centralized app store.

The F-Droid build for Zashi is completely reproducible. We encourage the community to build it and verify our work. This helps identify and mitigate potential threats to our infrastructure and processes, including those we depend on.

F-Droid Release Caveats 

Because F-Droid requires that all apps be 100% open-source, the F-Droid version of Zashi does not include Coinbase and Flexa integrations at this time. Although the source for these integrations is available, they depend on API keys that can’t be published, and had to be excluded from this release.

The F-Droid and Google Play Store releases are separate apps and do not share wallet data. You can install and run both at the same time with different seed phrases. If you need to move a wallet from one app to the other, first back up the seed phrase, then restore it in the other app.

Want All Features? Download Zashi from GitHub.

For Android users who want to bypass Google, but want full functionality or simply don’t want to wait for the app to become available on F-Droid, a binary release of Zashi for Android is available on GitHub today.

This is the same release that we publish to the Google Play Store. It includes all of Zashi’s latest features and integrations and is perfect for users who want to opt out of Google but still want the full Zashi experience. To install it you will need to know how to side-load apk files, for which tutorials are available.

Why no GitHub version for iOS?

Although Apple is now required to allow side-loading of iOS apps for users in the European Union, this comes with significant restrictions—including a minimum of 1 million downloads in the past calendar year for web distribution. While it is technically possible to build versions of Zashi for iOS similar to what we’ve delivered for Android, Apple’s terms still impose limitations on distribution and installs. We are investigating whether Zashi for iOS can be distributed through alternative app marketplaces.

Choose How You Zashi

With these new download options, Zashi will be accessible to Zcashers that want to use the app on their own terms:

Your wallet. Your choice.

Happy transacting. 

]]>
https://earlybirdsinvest.com/zashi-on-github-f-droid-more-ways-to-download/feed/ 0 20848