GitHub besieged by millions of malicious repositories in ongoing attack

'GitHub is struggling to contain an ongoing attack that’s flooding the site with millions of code repositories. These repositories contain obfuscated malware that steals passwords and cryptocurrency from developer devices, researchers said. The malicious repositories are clones of legitimate ones, making them hard to distinguish to the casual eye. An unknown party has automated a process that forks legitimate repositories, meaning the source code is copied so developers can use it in an independent project that builds on the original one. The result is millions of forks with names identical to the original one that add a payload that’s wrapped under seven layers of obfuscation. To make matters worse, some people, unaware of the malice of these imitators, are forking the forks, which adds to the flood.' -- source: https://arstechnica.com/security/2024/02/github-besieged-by-millions-of-mali... Cheers, Peter -- Peter Reutemann Dept. of Computer Science University of Waikato, Hamilton, NZ Mobile +64 22 190 2375 https://www.cs.waikato.ac.nz/~fracpete/ http://www.data-mining.co.nz/

On Thu, 29 Feb 2024 13:09:56 +1300, Peter Reutemann quoted:
'To make matters worse, some people, unaware of the malice of these imitators, are forking the forks, which adds to the flood.'
Surely GitHub would know when a fork has been made of a repo that is flagged as malicious, and block access to those forks and warn their creators.
participants (2)
-
Lawrence D'Oliveiro
-
Peter Reutemann