Malware deployed via fraudulent VS Code alerts on GitHub | brief

Threat actors have leveraged bogus VS Code security alerts to compromise GitHub developers with malware as part of a large-scale scam operation, according to BleepingComputer.Malicious vulnerability advisories with realistic titles published in the Discussions section of multiple GitHub projects contained links to patched instances of allegedly compromised VS Code extensions on Google Drive, which when clicked, enabled a cookie-based redirection chain diverting to drnatashachinn[.]com, a report from Socket revealed. The website facilitated the execution of a JavaScript reconnaissance script that exfiltrated system details, including timezones, user agents, OS information, and automation indicators, to profile targets and facilitate second-stage malware delivery to targeted victims alone.Such findings follow previous exploitation of GitHub notification systems for phishing and malware intrusions, with 12,000 GitHub repositories targeted with counterfeit security alerts to lure authorizations for an illicit OAuth app as part of a sweeping phishing campaign last year. Combating such a threat requires more stringent verification of vulnerability identifiers.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *