By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
Notification Show More
Latest News
Why a tiny American firm is taking aim at an Indian conglomerate
Uncategorized
‘It turned bad in an instant’: CNN crew has close call in Ukraine as Russian missiles pummel their location
Uncategorized
Offices are more than 50% filled for the first time since the pandemic started
Uncategorized
Advisory Firm Sues Elon Musk’s Twitter, Saying It Hasn’t Been Paid
Sports
Kirstie Alley, ‘Cheers’ and ‘Veronica’s Closet’ star, dead at 71
Uncategorized
Aa
  • Home
  • Politics
  • Business
  • LifeStyle
  • Sports
  • Entertainment
  • Health
  • Tech
Reading: Thousands of GitHub repositories are littered with malware
Share
Aa
Confluence News - Breaking News, Latest News and VideosConfluence News - Breaking News, Latest News and Videos
  • ES Money
  • U.K News
  • Entertainment
  • Science
  • Technology
  • Insider
Search
  • Home
  • Politics
  • Business
  • Sports
  • Entertainment
  • Health
  • Life Style
  • Tech
Have an existing account? Sign In
Follow US
Confluence News - Breaking News, Latest News and Videos > Blog > Tech > Thousands of GitHub repositories are littered with malware
Tech

Thousands of GitHub repositories are littered with malware

Last updated: 2022/10/24 at 1:53 PM
Share
SHARE

More than one in every ten GitHub repositories sharing exploit proof-of-concepts could be holding some form of malware or malicious content, putting software developers and cybersecurity researchers at plenty of risk, experts have found. 

GitHub is used, among other things, to share proof-of-concept (PoC) exploits for various vulnerabilities. That helps researchers and developers verify existing fixes and make sure their products and endpoints are safe from risky flaws.

A report from researchers at the Leiden Institute of Advanced Computer Science analyzing tens of thousands of such repositories found many were distributing fake PoCs which were, instead, holding malware.

Trojans and Cobalt Strike beacons

During the experiment, researchers analyzed roughly 47,300 repositories claiming to be a PoC for a flaw discovered between 2017 and 2021. 

They cross-referenced PoC publisher IPs to public blocklists, VT and AbuseIPDB, ran VirusTotal checks on the provided executables and their hashes, and decoded obfuscated files before running binary and IP checks.

Read more

> GitHub accounts are being stolen by fake CircleCI accounts

> GitHub is getting better at hunting down your dangerous code

> Here are the best antivirus programs right now

What they found was a total of 4,893 repositories being malicious in one way or another. Of the 150,734 unique IP addresses that were extracted, 2,864 were found on blocklists, 1,522 were previously flagged by VirusTotal, and 1,069 were found in AbuseIPDB’s database. Analyzing the binaries on 6,160 executables, researchers found 2,164 malicious samples, hosted in 1,398 repositories. 

All in all, the possibility of picking up malware instead of an actual PoC is around 10.3%, researchers concluded. Victims can be infected by a myriad of things, from remote access trojans to Cobalt Strike beacons.

After seeing the results, GitHub moved to remove the malicious content from its platform, but BleepingComputer found at least 60 examples are still pending removal.

These are the best firewalls right now

Via: BleepingComputer

 

You Might Also Like

I’ve reviewed laptops for decades; and this $499 Core i7 2-in1 laptop is perfect for freelancers

Sony’s new AV receivers with PS5 & Sonos support are the future-proof option we need

Many security teams are prioritizing prevention over detection, with disastrous results

YouTube’s Go Live Together lets you co-host a livestream – but there’s a catch

October 24, 2022
Share this Article
Facebook Twitter Email Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow US

Find US on Social Medias
Facebook Like
Twitter Follow
Youtube Subscribe
Telegram Follow

Weekly Newsletter

Subscribe to our newsletter to get our newest articles instantly!

[mc4wp_form]
Popular News
Top

Inside George Santos’ transformation from Anthony Devolder into a political figure CNN.com – RSS Channel – HP Hero

February 2, 2023
Watch: Bash asks Pelosi if McCarthy has what it takes to be House Speaker CNN.com – RSS Channel – HP Hero
Photos: Brazil begins paying final respects to legend Pele
China’s smartphone giant Xiaomi slashes workforce: reports
How the Buffalo Blizzard Became So Deadly
- Advertisement -
Ad imageAd image
Global Coronavirus Cases

Confirmed

0

Death

0

More Information:Covid-19 Statistics

Categories

  • ES Money
  • Insider
  • Science
  • Technology
  • LifeStyle

About US

We influence 20 million users and is the number one business and technology news network on the planet.
Quick Link
  • Economy
  • Politics
  • Life Style
  • Contact Us
Top Categories
  • Business
  • Tech
  • Top
  • Health
  • Entertainment

Subscribe US

Subscribe to our newsletter to get our newest articles instantly!

© confluencenews. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?