supply-chain
Network of 200 GitHub Repositories Used for Malware Infection
High
Summary
A threat actor, linked to previous activity associated with the ‘ischhfd83’ email address, has created a network of over 200 GitHub repositories delivering Windows malware through a Go module disguised as a DNS scanning tool. The module leverages public dead drops to deliver payloads including ratware, infostealers, and cryptominers, highlighting a sophisticated supply chain attack targeting open-source developers.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data