National Cyber Warfare Foundation (NCWF)

GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contributions


0 user ratings
2023-09-28 17:48:16
milo
Developers

 - archive -- 
A new malicious campaign has been observed hijacking GitHub accounts and committing malicious code disguised as Dependabot contributions with an aim to steal passwords from developers.
"The malicious code exfiltrates the GitHub project's defined secrets to a malicious C2 server and modify any existing javascript files in the attacked project with a web-form password-stealer malware code



Source: TheHackerNews
Source Link: https://thehackernews.com/2023/09/github-repositories-hit-by-password.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Developers



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.