malicious – Earlybirds Invest https://earlybirdsinvest.com Latest Crypto News Sat, 13 Sep 2025 03:08:01 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.7 https://i0.wp.com/earlybirdsinvest.com/wp-content/uploads/2024/12/cropped-New-Project-2024-12-17T235703.455.png?fit=32%2C32&ssl=1 malicious – Earlybirds Invest https://earlybirdsinvest.com 32 32 240146708 Malicious Repos Can Trigger Auto Code Execution in Cursor AI https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/ https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/#respond Sat, 13 Sep 2025 03:08:00 +0000 https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/

Oasis Security has identified a vulnerability in Cursor, an AI-based code editor, that allows hidden code to run as soon as a user opens a project folder without any action or warning.

The issue comes from a default setting in Cursor. A safety feature called Workspace Trust is disabled by default when the program is first installed. As a result, certain task files can begin executing commands immediately when a developer opens a folder.

If a user adds a harmful task to a project and shares it online, those commands will run as soon as another person opens the folder in Cursor.

Candlesticks, Trendlines & Patterns Easily Explained (Animated Examples)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Cursor is built on top of Visual Studio Code, which also includes the Workspace Trust feature. This tool is designed to protect developers from malicious code by blocking automatic tasks from unknown sources.

The vulnerability exploits the .vscode/tasks.json file, which can contain instructions to run tasks as soon as a folder is opened. Attackers can place these instructions in a shared project.

According to Erez Schwartz from Oasis Security, this behavior can lead to stolen credentials, changed files, or system access. It also increases the chances of supply chain attacks, where malicious code spreads through tools or projects used by many people.

To stay safe, users should take a few steps. First, they should enable Workspace Trust in Cursor to stop unknown tasks from running automatically. Second, it is advised to open untrusted projects using a different code editor, especially the .vscode folder, before using Cursor.

On August 28, Anthropic warned that bad actors are using its chatbot Claude to help carry out online crimes. How? Read the full story.


]]>
https://earlybirdsinvest.com/malicious-repos-can-trigger-auto-code-execution-in-cursor-ai/feed/ 0 58156
Threat actors abuse X’s Grok AI to spread malicious links https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/ https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/#respond Thu, 04 Sep 2025 05:17:08 +0000 https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/

X

Threat actors are using Grok, X’s built-in AI assistant, to bypass link posting restrictions that the platform introduced to reduce malicious advertising.

As discovered by Guardio Labs’ researcher Nati Tal, mavertisers often run sketchy video ads containing adult content baits and avoid including a link to the main body to avoid being blocked by X.

Instead, they hide it in the small “From:” metadata field under the video card, which apparently isn’t scanned by the social media platform for malicious links.

Hiding the malicious link in an ignored field
Hiding the malicious link in an ignored field
Source: @bananahacks

Next, (likely) the same actors ask Grok via a reply to the ad something about the post, like “where is this video from,” or “what is the link to this video.”

Grok parses the hidden “From:” field and replies with the full malicious link in clickable format, allowing users to click it and go straight to the malicious site.

Because Grok is automatically a trusted system account on the X platform, its post boosts the link’s credibility, reach, SEO, and reputation, increasing the likelihood that it will be broadcast to a large number of users.

The researcher has found that many of these links funnel through shady ad networks, leading to scams such as fake CAPTCHA tests, information-stealing malware, and other malicious payloads.

Instead of being blocked by X, they are instead promoted to users on the platform via malicious ads that receive a further boost from Grok.

Tal calls the technique of exploiting this loophole “Grokking,” and notes that it’s very effective, in some cases amplifying malicious ads to reach millions of impressions, as shown below.

Potential solutions include scanning all fields, blocking hidden links, and adding context sanitization to Grok, so the AI assistant does not blindly echo links when asked by users, but instead filters and checks them against blocklists.

Tal confirmed to us that he has contacted X to report the issue and received unofficial confirmation that Grok engineers received the report. 

BleepingComputer has also contacted X to ask if they’re aware of this abuse and whether they plan to do anything about it, but we received no response by publication time.

Picus Blue Report 2025

46% of environments had passwords cracked, nearly doubling from 25% last year.

Get the Picus Blue Report 2025 now for a comprehensive look at more findings on prevention, detection, and data exfiltration trends.

]]>
https://earlybirdsinvest.com/threat-actors-abuse-xs-grok-ai-to-spread-malicious-links/feed/ 0 56665
Apple patches iOS zero-day that put crypto wallets at risk via malicious images https://earlybirdsinvest.com/apple-patches-ios-zero-day-that-put-crypto-wallets-at-risk-via-malicious-images/ https://earlybirdsinvest.com/apple-patches-ios-zero-day-that-put-crypto-wallets-at-risk-via-malicious-images/#respond Fri, 22 Aug 2025 12:37:00 +0000 https://earlybirdsinvest.com/apple-patches-ios-zero-day-that-put-crypto-wallets-at-risk-via-malicious-images/

Apple released iOS 18.6.2 and iPadOS 18.6.2 on Aug. 20, 2025, along with macOS Sequoia 15.6.1, Sonoma 14.7.8, and Ventura 13.7.8, to fix a zero-day in the ImageIO framework that was exploited in the wild.

Per Apple, processing a malicious image could corrupt memory, enabling code execution, and the company is aware of a report of use in an extremely sophisticated attack targeting specific individuals.

The flaw sits in ImageIO, the component that parses common image formats, which makes delivery via everyday channels, including messaging apps and web content, straightforward from an attacker’s perspective. As security outlets reported, the bug is tracked as CVE-2025-43300 and stems from an out-of-bounds write that Apple addressed with improved bounds checking.

The crypto angle is direct. Wallet owners often copy and paste recipient addresses, and many keep recovery phrases in screenshots or photo storage for convenience. Research this year documented families of mobile spyware and stealers that scan galleries using optical character recognition and exfiltrate images with seed phrases, as well as strains that monitor the clipboard to swap addresses during a transaction.

As Kaspersky reported, SparkCat and its successor SparkKitty used OCR to harvest seed phrases from photos on both iOS and Android, including samples observed on official app stores.

A compromise achieved through a booby-trapped image can, therefore, act as an initial foothold to enable gallery scraping for recovery phrases, surveillance of crypto app activity, and clipboard hijacking during on-chain transfers. Previous research on clipboard hijackers explains how address strings are silently replaced to redirect funds during copy-paste, a tactic long used by drainer operations.

The current incident also fits a pattern of high-value iOS exploit chains used against targeted users. In 2023, Citizen Lab documented a zero-click chain, dubbed Blastpass, used to deliver commercial spyware, demonstrating how image and message parsing bugs can be linked for device takeover without user interaction.

That historical baseline, coupled with Apple’s acknowledgment of real-world use in the present case, frames the risk for crypto users who rely on mobile devices as primary signing endpoints.

Impact spans recent iPhone models and iPads covered by iOS 18 and iPadOS 18, including iPhone XS and later, plus supported Macs on Sequoia, Sonoma, and Ventura. Users can verify protection by confirming iOS or iPadOS 18.6.2, macOS Sequoia 15.6.1, Sonoma 14.7.8, or Ventura 13.7.8 in Settings, then rebooting after installation.

Security outlets urged immediate updates following Apple’s release and disclosure.

For a crypto-savvy audience, the operational takeaway is to close exposure by updating and to reduce post-exploit blast radius by moving seed storage off photo libraries, reviewing app photo permissions, limiting clipboard access, and treating mobile wallets as hot environments with strict hygiene.

Apple’s notes state the root cause was an out-of-bounds write in ImageIO that is now mitigated with stricter bounds checks, and the company confirmed exploitation reports when shipping the patch.

Mentioned in this article
]]>
https://earlybirdsinvest.com/apple-patches-ios-zero-day-that-put-crypto-wallets-at-risk-via-malicious-images/feed/ 0 54551
JSCEAL Scam Targets Crypto Users with 35,000 Malicious Ads https://earlybirdsinvest.com/jsceal-scam-targets-crypto-users-with-35000-malicious-ads/ https://earlybirdsinvest.com/jsceal-scam-targets-crypto-users-with-35000-malicious-ads/#respond Mon, 04 Aug 2025 03:18:19 +0000 https://earlybirdsinvest.com/jsceal-scam-targets-crypto-users-with-35000-malicious-ads/

Cybersecurity company Check Point has warned that over 10 million people may have been exposed to malware through fake crypto apps promoted via online ads.

The campaign, known as “JSCEAL”, has been active since at least March 2024, according to a July 29 report by Check Point.

It works by imitating nearly 50 well-known cryptocurrency platforms, including Binance



$5.76B

and Kraken



$195.4M

, to trick users into downloading harmful software.

How to Use Crypto? 5 Rewarding Strategies Explained (Animated)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

Check Point stated that Meta’s internal data showed over 35,000 such ads were displayed in early 2025. The firm estimated that at least 3.5 million people in the EU saw these ads.

Since the campaign also mimicked platforms in Asia, where social media use is widespread, the global reach is believed to be much higher. However, Check Point explained that not every view results in infection, and the total number of actual victims is hard to confirm.

The malware is built with JavaScript, which runs without needing any further input from the user. Check Point said the code is hard to examine because it is heavily disguised.

If installed, the malware collects private information from the device. This includes things like keyboard activity that can reveal passwords, Telegram session data, stored login credentials, and browser cookies.

It can also affect crypto wallet browser extensions like MetaMask, which may increase the risk of unauthorized access.

Recently, Sentinel Labs discovered a hacking campaign that uses fake video meetings and disguised software updates to plant malware on Apple computers. How does the malware work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/jsceal-scam-targets-crypto-users-with-35000-malicious-ads/feed/ 0 51335
Hackers breach Toptal GitHub account, publish malicious npm packages https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/ https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/#respond Thu, 24 Jul 2025 15:13:12 +0000 https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/

NPM

Hackers compromised Toptal’s GitHub organization account and used their access to publish ten malicious packages on the Node Package Manager (NPM) index.

The packages included data-stealing code that collected GitHub authentication tokens and then wiped the victims’ systems.

Toptal is a freelance talent marketplace that connects companies with software developers, designers, and finance experts. The company also maintains internal developer tools and design systems, most notably Picasso, which they make available through GitHub and NPM.

Attackers hijacked Toptal’s GitHub organization on July 20, and almost immediately made public all 73 of the repositories available, exposing private projects and source code.

Tweet

In the days that followed, the attackers modified the source code of Picasso on GitHub to include malware and published 10 malicious packages on NPM as Toptal, making them appear as legitimate updates.

The malicious packages and modified versions are:

  • @toptal/picasso-tailwind (v3.1.0)
  • @toptal/picasso-charts (v59.1.4)
  • @toptal/picasso-shared (v15.1.0)
  • @toptal/picasso-provider (v5.1.1)
  • @toptal/picasso-select (v4.2.2)
  • @toptal/picasso-quote (v2.1.7)
  • @toptal/picasso-forms (v73.3.2)
  • @xene/core (v0.4.1)
  • @toptal/picasso-utils (v3.2.0)
  • @toptal/picasso-typography (v4.1.4)

The malicious packages were downloaded roughly 5,000 times before being detected, likely infecting developers with malware.

The hackers injected the malicious code into ‘package.json’ files to add two functions: steal data (‘preinstall’ script) and wipe hosts (‘postinstall’ script).

The first extracts the victim’s CLI authentication token and sends it to an attacker-controlled webhook URL, granting them unauthorized access to the target’s GitHub account.

After exfiltrating the data, the second script attempts to delete the entire filesystem with ‘sudo rm -rf –no-preserve-root /’ on Linux systems, or recursively and silently delete files on Windows.

According to code security platform Socket, Toptal deprecated the malicious packages on July 23 and reverted to safe versions, but issued no public statement to alert users who had downloaded the malicious releases to the risks.

Although the initial compromise method remains unknown, Socket lists multiple possibilities ranging from insider threats to phishing attacks targeting Toptal developers.

BleepingComputer has contacted Toptal for a statement, but we are still waiting for their response.

If you have installed any of the malicious packages, you are advised to revert to a previous stable version as soon as possible.

Wiz

Contain emerging threats in real time – before they impact your business.

Learn how cloud detection and response (CDR) gives security teams the edge they need in this practical, no-nonsense guide.

]]>
https://earlybirdsinvest.com/hackers-breach-toptal-github-account-publish-malicious-npm-packages/feed/ 0 49418
Hacker Slips Malicious Code Into Ethereum Dev Tool ETHcode https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/ https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/#respond Fri, 11 Jul 2025 17:06:14 +0000 https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/

Cybersecurity researchers at ReversingLabs recently found that a hacker injected harmful code into ETHcode, a toolset for Ethereum
ETH


$2,962.49

developers.

ETHcode is a VS Code extension that helps developers build and test Ethereum-compatible smart contracts and apps.

The suspicious code was added on June 17 by a GitHub user named Airez299, who had no earlier contributions to the project.

What is Staking Crypto? (Rewards & Risks Explained SIMPLY)

Did you know?

Want to get smarter & wealthier with crypto?

Subscribe – We publish new crypto explainer videos every week!

The update included 43 separate changes and about 4,000 edited lines, which mainly described a new testing system and additional features. Inside this large batch, two lines of malicious code were hidden.

The update was reviewed by GitHub’s automated AI tool and also checked by 7finney, the team that manages ETHcode. Neither spotted the problem, and only small edits were requested before approval.

According to ReversingLabs, the harmful code was disguised in a way that made it hard to notice. The first line was placed in a file with a name almost identical to an existing one and written in a scrambled style to make it harder to read.

The second line was designed to activate the first. When triggered, it launched a PowerShell script that downloaded and ran a batch file from a public file-sharing site.

ReversingLabs noted that it was likely designed to steal cryptocurrency stored on the victim’s computer or interfere with Ethereum projects being developed using the tool.

Recently, Sentinel Labs discovered a hacking campaign linked to groups in North Korea that uses malware called NimDoor. How does the malware work? Read the full story.

Having completed a Master’s degree in Economics, Politics, and Cultures of the East Asia region, Aaron has written scientific papers analyzing the differences between Western and Collective forms of capitalism in the post-World War II era.
With close to a decade of experience in the FinTech industry, Aaron understands all of the biggest issues and struggles that crypto enthusiasts face. He’s a passionate analyst who is concerned with data-driven and fact-based content, as well as that which speaks to both Web3 natives and industry newcomers.
Aaron is the go-to person for everything and anything related to digital currencies. With a huge passion for blockchain & Web3 education, Aaron strives to transform the space as we know it, and make it more approachable to complete beginners.
Aaron has been quoted by multiple established outlets, and is a published author himself. Even during his free time, he enjoys researching the market trends, and looking for the next supernova.


]]>
https://earlybirdsinvest.com/hacker-slips-malicious-code-into-ethereum-dev-tool-ethcode/feed/ 0 47061
Malicious PyPi package hides RAT malware, targets Discord devs since 2022 https://earlybirdsinvest.com/malicious-pypi-package-hides-rat-malware-targets-discord-devs-since-2022/ https://earlybirdsinvest.com/malicious-pypi-package-hides-rat-malware-targets-discord-devs-since-2022/#respond Thu, 08 May 2025 19:25:05 +0000 https://earlybirdsinvest.com/malicious-pypi-package-hides-rat-malware-targets-discord-devs-since-2022/

Discord

A malicious Python package targeting Discord developers with remote access trojan (RAT) malware was spotted on the Python Package Index (PyPI) after more than three years.

Named “discordpydebug,” the package was masquerading as an error logger utility for developers working on Discord bots and was downloaded over 11,000 times since it was uploaded on March 21, 2022, even though it has no description or documentation.

Cybersecurity company Socket, which first spotted it, says the malware could be used to backdoor Discord developers’ systems and provide attackers with data theft and remote code execution capabilities.

“The package targeted developers who build or maintain Discord bots, typically indie developers, automation engineers, or small teams who might install such tools without extensive scrutiny,” Socket researchers said.

“Since PyPI doesn’t enforce deep security audits of uploaded packages, attackers often take advantage of this by using misleading descriptions, legitimate-sounding names, or even copying code from popular projects to appear trustworthy.”

Once installed, the malicious package transforms the device into a remote-controlled system that will execute instructions sent from an attacker-controlled command-and-control (C2) server.

The attackers could use the malware to gain unauthorized access to credentials and more (e.g., tokens, keys, and config files), steal data and monitor system activity without being detected, remotely execute code for deploying further malware payloads, and obtain information that can help them move laterally within the network.

discordpydebug on PyPI
discordpydebug on PyPI (BleepingComputer)

​While the malware lacks persistence or privilege escalation mechanisms, it uses outbound HTTP polling instead of inbound connections, making it possible to bypass firewalls and security software, especially in loosely controlled development environments.

Once installed, the package silently connects to an attacker-controlled command-and-control (C2) server (backstabprotection.jamesx123.repl[.]co), sending a POST request with a “name” value to add the infected host to the attackers’ infrastructure.

The malware also includes functions to read from and write to files on the host machine using JSON operations when triggered by specific keywords from the C2 server, giving the threat actors visibility into sensitive data.

To mitigate the risk of installing backdoored malware from online code repositories, software developers should ensure that the packages they download and install come from the official author before installation, especially for popular ones, to avoid typosquatting.

Additionally, when using open-source libraries, they should review the code for suspicious or obfuscated functions and consider using security tools to detect and block malicious packages.

Red Report 2025

Based on an analysis of 14M malicious actions, discover the top 10 MITRE ATT&CK techniques behind 93% of attacks and how to defend against them.

]]>
https://earlybirdsinvest.com/malicious-pypi-package-hides-rat-malware-targets-discord-devs-since-2022/feed/ 0 35122
Malicious npm package secretly targets Atomic, Exodus wallets to intercept and reroutes funds https://earlybirdsinvest.com/malicious-npm-package-secretly-targets-atomic-exodus-wallets-to-intercept-and-reroutes-funds/ https://earlybirdsinvest.com/malicious-npm-package-secretly-targets-atomic-exodus-wallets-to-intercept-and-reroutes-funds/#respond Tue, 15 Apr 2025 06:03:40 +0000 https://earlybirdsinvest.com/malicious-npm-package-secretly-targets-atomic-exodus-wallets-to-intercept-and-reroutes-funds/

Researchers have discovered a malicious software package uploaded to npm that secretly alters locally installed versions of crypto wallets and allows attackers to intercept and reroute digital currency transactions, ReversingLabs revealed in a recent report.

The campaign injected trojanized code into locally installed Atomic and Exodus wallet software and hijacked crypto transfers. The attack centered on a deceptive npm package, pdf-to-office, which posed as a library for converting PDF files to Office formats.

When executed, the package silently located and modified specific versions of Atomic and Exodus wallets on victims’ machines, redirecting outgoing crypto transactions to wallets controlled by threat actors.

ReversingLabs said the campaign exemplifies a broader shift in tactics: rather than directly compromising open-source libraries, which often triggers swift community responses, attackers are increasingly distributing packages designed to “patch” local installations of trusted software with stealthy malware.

Targeted file patching

The pdf-to-office package was first uploaded to npm in March and updated multiple times through early April. Despite its stated function, the package lacked actual file conversion features.

Instead, its core script executed obfuscated code that searched for local installations of Atomic Wallet and Exodus Wallet and overwrote key application files with malicious variants.

The attackers replaced legitimate JavaScript files inside the resources/app.asar archive with near-identical trojanized versions that substituted the user’s intended recipient address with a base64-decoded wallet belonging to the attacker.

For Atomic Wallet, versions 2.90.6 and 2.91.5 were specifically targeted. Meanwhile, a similar method was applied to Exodus Wallet versions 25.9.2 and 25.13.3.

Once modified, the infected wallets would continue redirecting funds even if the original npm package was deleted. Full removal and reinstallation of the wallet software were required to eliminate the malicious code.

ReversingLabs also noted the malware’s attempts at persistence and obfuscation. Infected systems sent installation status data to an attacker-controlled IP address (178.156.149.109), and in some cases, zipped logs and trace files from AnyDesk remote access software were exfiltrated, suggesting an interest in deeper system infiltration or evidence removal.

Expanding software supply chain threats

The discovery follows a similar March campaign involving ethers-provider2 and ethers-providerz, which patched the ethers npm package to establish reverse shells. Both incidents highlight the rising complexity of supply chain attacks targeting the crypto space.

ReversingLabs warned that these threats continue to evolve, especially in web3 environments where local installations of open-source packages are common. Attackers increasingly rely on social engineering and indirect infection methods, knowing that most organizations fail to scrutinize already installed dependencies.

According to the report:

“This kind of patching attack remains viable because once the package is installed and the patch is applied, the threat persists even if the source npm module is removed.”

The malicious package was flagged by ReversingLabs’ machine-learning algorithms under Threat Hunting policy TH15502. It has since been removed from npm, but a republished version under the same name and version 1.1.2 briefly reappeared, indicating the threat actor’s persistence.

Investigators published hashes of affected files and wallet addresses used by the attackers as indicators of compromise (IOCs). These include wallets used for illicit fund redirection, as well as the SHA1 fingerprints of all infected package versions and associated trojanized files.

As software supply chain attacks become more frequent and technically refined, especially in the digital asset space, security experts are calling for stricter code auditing, dependency management, and real-time monitoring of local application changes.

Mentioned in this article
]]>
https://earlybirdsinvest.com/malicious-npm-package-secretly-targets-atomic-exodus-wallets-to-intercept-and-reroutes-funds/feed/ 0 30863
Malicious GitHub repositories deploying hidden attacks on crypto wallets https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/ https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/#respond Wed, 26 Feb 2025 12:14:12 +0000 https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/

Kaspersky researchers have identified an attack vector on GitHub that uses repositories to distribute code that targets crypto wallets.

The investigation revealed a campaign dubbed GitVenom, in which threat actors created hundreds of GitHub repositories purporting to offer utilities for social media automation, wallet management, and even gaming enhancements.

Although these repositories were designed to resemble legitimate open-source projects, their code failed to deliver the advertised functions. Instead, it embedded instructions to install cryptographic libraries, download additional payloads, and execute hidden scripts.

GitVenom repos

The malicious code appears across Python, JavaScript, C, C++, and C# projects. In Python-based repositories, a lengthy sequence of tab characters precedes commands that install packages like cryptography and fernet, ultimately decrypting and running an encrypted payload.

JavaScript projects incorporate a function that decodes a Base64-encoded script, triggering the malicious routine.

Similarly, in projects using C, C++, and C#, a concealed batch script within Visual Studio project files activates at build time. Per Kaspersky’s report, each payload is configured to fetch further components from an attacker-controlled GitHub repository.

These additional components include a Node.js stealer that collects saved credentials, digital wallet data, and browsing history before packaging the information into an archive for exfiltration via Telegram.

Open-source tools such as the AsyncRAT implant and the Quasar backdoor are also used to facilitate remote access. A clipboard hijacker that scans for crypto wallet addresses and replaces them with those controlled by the attackers is also used. 

Attack vector is not new

The campaign, which has been active for several years with some repositories originating two years ago, has triggered infection attempts worldwide. Telemetry data indicate that attempts linked to GitVenom have been most prominent in Russia, Brazil, and Turkey.

Kaspersky researchers stressed the importance of scrutinizing third-party code before execution, noting that open-source platforms, while essential to collaborative development, can also serve as conduits for malware when repositories are manipulated to mimic authentic projects.

Developers are advised to double-check the contents and activity of GitHub repositories before integrating code into their projects.

The report outlines that these projects use AI to artificially inflate commit histories and craft detailed README files. Thus, when reviewing a new repo, developers should check for overly verbose language, formulaic structure, and even leftover AI instructions or responses in these areas.

While using AI to help craft a README file is not a red flag in itself, identifying it should spur developers to investigate further before using the code. Looking for community engagement, reviews, and other projects using the repo may aid with this. However, fake AI-generated reviews and social media posts also make this a tough challenge.

Blocscale
]]>
https://earlybirdsinvest.com/malicious-github-repositories-deploying-hidden-attacks-on-crypto-wallets/feed/ 0 21983
Apiiro unveils free scanner to detect malicious code merges https://earlybirdsinvest.com/apiiro-unveils-free-scanner-to-detect-malicious-code-merges/ https://earlybirdsinvest.com/apiiro-unveils-free-scanner-to-detect-malicious-code-merges/#respond Fri, 21 Feb 2025 06:12:20 +0000 https://earlybirdsinvest.com/apiiro-unveils-free-scanner-to-detect-malicious-code-merges/

Scanner

Security researchers at Apiiro have released two free, open-source tools designed to detect and block malicious code before they are added to software projects to curb supply chain attacks.

The two tools consist of a comprehensive ruleset for Semgrep and Opengrep designed to detect malicious code patterns with minimal false positives and PRevent, a GitHub-integrated scanner, that detects and alerts on suspicious code in pull requests (PRs).

According to Apiiro’s security researcher Matan Giladi, the tools have a minimal false positive detection rate, making them particularly valuable in real-world practice.

Specifically, the detection accuracy of the ruleset for PyPI packages is 94.3%, while it drops to the still impressive 88.4% for npm packages. PRevent successfully flags malicious PRs in 91.5% of the examined cases.

Detection test results
Detection test results
Source: Apiiro

Catching malicious code

Apiiro’s malicious code detection strategy is based on identifying “code anti-patterns,” which are suspicious patterns in code that demonstrate behaviors that are rare in legitimate code but common in malware.

The detection system uses static analysis, meaning it examines code without executing it, keeping the environment safe from accidental infections.

These anti-patterns include:

  • Various obfuscation methods like encoding, nested transformations, and runtime modifications that help hide the code’s functionality and intent.
  • Use of exec(), eval(), or similar functions, which allow arbitrary code execution at runtime.
  • Code that downloads and executes remote payloads from external, unknown servers.
  • Methods for exfiltrating sensitive user data to external locations.

This ruleset can be integrated into CI/CD pipelines for automatic repository scanning, used for scanning npm and PyPI packages, or adapted to other platforms using Semgrep or Opengrep.

PRevent, which uses the same anti-patterns, is designed to scan pull request events in real-time before code is merged, stopping any threats before they reach production.

PRevent warns about malicious code in the PR
PRevent warns about malicious code in the PR
Source: Apiiro

It can be set to block the merging until an authorized reviewer approves it or add comments on detected issues to ensure developers are alerted of the risks.

Issue prompting review
Issue prompting review
Source: Apiiro

Apiiro acknowledges that its tools are still practically limited, as they cannot detect malware hidden in compiled binaries nor scan npm and PyPI packages directly, but plans to add more features like deep code analysis and AI-assisted scans in future updates.

Both the malicious code detection ruleset and the PRevent tool are available for free on GitHub, with instructions on how to use them.

BleepingComputer has not tested these security tools and cannot guarantee their effectiveness or safety.

]]>
https://earlybirdsinvest.com/apiiro-unveils-free-scanner-to-detect-malicious-code-merges/feed/ 0 20875