Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
  • Home
  • Crypto
    • Altcoins
    • Bitcoin
    • Ethereum
    • Monero
    • XRP
    • Zcash
  • Web3
  • DeFi
  • NFTs
No Result
View All Result
Altszn.com
No Result
View All Result

GitHub faces widespread malware attacks affecting projects, including crypto

Altszn.com by Altszn.com
August 3, 2022
in Crypto
0
GitHub faces widespread malware attacks affecting projects, including crypto
399
SHARES
2.3k
VIEWS
Share on FacebookShare on Twitter


Major developer platform GitHub faced a widespread malware attack and reported 35,000 “code hits” on a day that saw thousands of Solana-based wallets drained for millions of dollars.

The widespread attack was highlighted by GitHub developer Stephen Lucy, who first reported the incident earlier on Wednesday. The developer came across the issue while reviewing a project he found on a Google search.

I am uncovering what seems to be a massive widespread malware attack on @github.

– Currently over 35k repositories are infected
– So far found in projects including: crypto, golang, python, js, bash, docker, k8s
– It is added to npm scripts, docker images and install docs pic.twitter.com/rq3CBDw3r9

— Stephen Lacy (@stephenlacy) August 3, 2022

So far, various projects — from crypto, Golang, Python, JavaScript, Bash, Docker and Kubernetes — have been found to be affected by the attack. The malware attack is targeted at the docker images, install docs and NPM script, which is a convenient way to bundle common shell commands for a project.

To dupe developers and access critical data, the attacker first creates a fake repository (a repository contains all of the project’s files and each file’s revision history) and pushes clones of legit projects to GitHub. For example, the following two snapshots show this legit crypto miner project and its clone.

Original crypto mining project. Source: Github
Cloned crypto mining project. Source: Github

Many of these clone repositories were pushed as “pull requests,” which let developers tell others about changes they have pushed to a branch in a repository on GitHub.

Related: Nomad reportedly ignored security vulnerability that led to $190M exploit

Once the developer falls prey to the malware attack, the entire environment variable (ENV) of the script, application or laptop (Electron apps) is sent to the attacker’s server. The ENV includes security keys, Amazon Web Services access keys, crypto keys and much more.

The developer has reported the issue to GitHub and advised developers to GPG-sign their revisions made to the repository. GPG keys add an extra layer of security to GitHub accounts and software projects by providing a way of verifying all revisions come from a trusted source.

‏‏‎ ‎





Read More: cointelegraph.com

Tags: AffectingAttacksBlockchainCryptoFacesGithubIncludingMalwareProjectswidespread
ADVERTISEMENT

Recent

AI a powerful tool for devs to change gaming, says former Google gaming head

AI a powerful tool for devs to change gaming, says former Google gaming head

October 2, 2023
Bitfarms increases mining pace, generates 411 BTC in September

Bitfarms increases mining pace, generates 411 BTC in September

October 2, 2023
Hitachi Leverages Metaverse and VR for Next-Generation Workforce Training

Hitachi Leverages Metaverse and VR for Next-Generation Workforce Training

October 2, 2023

Categories

  • Altcoins (265)
  • Bitcoin (8,366)
  • Blockchain (9,283)
  • Crypto (12,576)
  • Dark Web (816)
  • DeFi (5,946)
  • Ethereum (3,970)
  • Exchanges (421)
  • Metaverse (6,587)
  • Monero (490)
  • NFT (3,980)
  • Psychedelic Stocks (524)
  • Solana (2,872)
  • Web3 (13,166)
  • Zcash (412)

Category

Advertise

Advertise your site, company or product to millions of web3, NFT and cryptocurrency enthusiasts. Learn more

Useful Links

Advertise
DMCA
Contact Us
Privacy Policy
Shipping & Returns
Terms of Use

Resources

Exchanges
Changelly
Web3 Jobs

Recent News

AI a powerful tool for devs to change gaming, says former Google gaming head

AI a powerful tool for devs to change gaming, says former Google gaming head

October 2, 2023
Bitfarms increases mining pace, generates 411 BTC in September

Bitfarms increases mining pace, generates 411 BTC in September

October 2, 2023

© 2022 Altszn.com. All Rights Reserved.

No Result
View All Result
  • Home
    • Home – Layout 1
    • Home – Layout 2
    • Home – Layout 3

© Altszn.com. All Rights Reserved.

  • bitcoinBitcoin (BTC) $ 28,401.00
  • ethereumEthereum (ETH) $ 1,725.43
  • tetherTether (USDT) $ 1.00
  • bnbBNB (BNB) $ 218.76
  • xrpXRP (XRP) $ 0.522936
  • usd-coinUSDC (USDC) $ 0.999448
  • staked-etherLido Staked Ether (STETH) $ 1,729.23
  • solanaSolana (SOL) $ 23.93
  • cardanoCardano (ADA) $ 0.267922
  • dogecoinDogecoin (DOGE) $ 0.063482
  • tronTRON (TRX) $ 0.089303
  • the-open-networkToncoin (TON) $ 2.06
  • polkadotPolkadot (DOT) $ 4.23
  • matic-networkPolygon (MATIC) $ 0.563586
  • litecoinLitecoin (LTC) $ 67.53
  • bitcoin-cashBitcoin Cash (BCH) $ 246.45
  • wrapped-bitcoinWrapped Bitcoin (WBTC) $ 28,421.00
  • shiba-inuShiba Inu (SHIB) $ 0.000008
  • chainlinkChainlink (LINK) $ 7.90
  • daiDai (DAI) $ 0.999837
  • uniswapUniswap (UNI) $ 4.60
  • true-usdTrueUSD (TUSD) $ 0.999877
  • avalanche-2Avalanche (AVAX) $ 9.66
  • leo-tokenLEO Token (LEO) $ 3.67
  • stellarStellar (XLM) $ 0.113952
  • moneroMonero (XMR) $ 149.30
  • okbOKB (OKB) $ 43.94
  • ethereum-classicEthereum Classic (ETC) $ 16.58
  • binance-usdBUSD (BUSD) $ 1.00
  • cosmosCosmos Hub (ATOM) $ 7.43
  • hedera-hashgraphHedera (HBAR) $ 0.051540
  • filecoinFilecoin (FIL) $ 3.42
  • lido-daoLido DAO (LDO) $ 1.64
  • internet-computerInternet Computer (ICP) $ 3.25
  • mantleMantle (MNT) $ 0.421843
  • crypto-com-chainCronos (CRO) $ 0.051639
  • makerMaker (MKR) $ 1,485.80
  • aptosAptos (APT) $ 5.59
  • quant-networkQuant (QNT) $ 90.32
  • vechainVeChain (VET) $ 0.017631
  • arbitrumArbitrum (ARB) $ 0.977538
  • optimismOptimism (OP) $ 1.46
  • nearNEAR Protocol (NEAR) $ 1.15
  • kaspaKaspa (KAS) $ 0.050169
  • aaveAave (AAVE) $ 69.68
  • rocket-pool-ethRocket Pool ETH (RETH) $ 1,875.99
  • the-graphThe Graph (GRT) $ 0.091443
  • algorandAlgorand (ALGO) $ 0.103596
  • whitebitWhiteBIT Coin (WBT) $ 5.20
  • blockstackStacks (STX) $ 0.528723