Saturday, May 31, 2025
News Wave
No Result
View All Result
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology
News Wave
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology
No Result
View All Result
News Wave
No Result
View All Result
Home Technology

GitHub malware spreads by hackers spoofing Microsoft files

22 April 2024
in Technology
0 0
GitHub malware spreads by hackers spoofing Microsoft files
Share on FacebookShare on Twitter



There have been reports of hackers finding a way to upload malware to GitHub, making it appear as if it was hosted and distributed by legitimate operators. McAfee cybersecurity researchers recently discovered the LUA malware loader being distributed through a repository that seemed to belong to Microsoft on GitHub.

The malware uploaded to GitHub has unique features that make it difficult to detect. For example, a link to the malware may appear as follows: https://github[.]com/microsoft/vcpkg/files/14125503/Cheat.Lab.2.7.2.zip. However, attempting to locate the .zip file in the vcpkg library directly will yield no results.

It seems that users can upload files when leaving a comment on a commit or issue. These files are automatically uploaded, generating a link like the one mentioned above. Users can post and delete the comment quickly, but the file will remain uploaded and accessible, even without posting the comment.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features, and guidance your business needs to succeed!

It is unclear if this behavior is a bug or an intentional feature on GitHub’s part. BleepingComputer reports that victim companies have limited options to protect themselves from impersonation. Disabling comments is a possible solution, but it can create more issues as legitimate users often use comments to report bugs or provide suggestions. Furthermore, comments can only be disabled for a maximum of six months at a time.

More from TechRadar Pro



Source link

Tags: FilesGitHubhackersmalwareMicrosoftspoofingspreads
Previous Post

People Complaining About NHS Appointments Being Too Quick Resurfaces

Next Post

Indonesia’s Top Court Clears Way for Prabowo’s Presidency

Related Posts

Trump pulls Isaacman nomination for space. Source: “NASA is f***ed”
Technology

Trump pulls Isaacman nomination for space. Source: “NASA is f***ed”

by My News Wave
31 May 2025
0

The Trump administration has confirmed the withdrawal of private astronaut Jared Isaacman's nomination to lead NASA, reportedly due to concerns over his political loyalty. White House Spokesperson Liz Huston emphasized the importance of the NASA Administrator aligning with President Trump's America First agenda, which includes ambitious plans for space exploration, such as a mission to Mars. A replacement for Isaacman will be announced by President Trump in the near future. Full Article

Read more
Judge Rejects Claim AI Chatbots Protected By First Amendment in Teen Suicide Lawsuit
Technology

Judge Rejects Claim AI Chatbots Protected By First Amendment in Teen Suicide Lawsuit

by My News Wave
31 May 2025
0

A U.S. federal judge ruled that First Amendment free-speech protections do not exempt Character.AI from a lawsuit filed by Megan Garcia, the mother of 14-year-old Sewell Setzer III, who died by suicide after interacting with Character.AI chatbots. Judge Anne C. Conway dismissed the defendants' motions to dismiss, stating that the output of AI chatbots trained by large language models does not qualify as speech. In response, Character.AI has implemented safety features, including under-18 chatbots and...

Read more
What's in the US Government's New Strategic Reserve of Seized Crytocurrencies?
Technology

What's in the US Government's New Strategic Reserve of Seized Crytocurrencies?

by My News Wave
31 May 2025
0

In March, an executive order mandated the creation of two stockpiles of crypto assets, alongside traditional reserves, with an estimated value of over $21 billion, primarily sourced from cryptocurrency seized in federal proceedings. According to Chainalysis, the U.S. government's top 20 crypto holdings include approximately $20.4 billion in Bitcoin and $493 million in other digital assets, such as Ethereum and various stablecoins, raising concerns among crypto enthusiasts about the potential conflict with the decentralized ethos...

Read more
Day 3 of the TechCrunch Sessions: AI Trivia Countdown — Your next shot at winning big
Technology

Day 3 of the TechCrunch Sessions: AI Trivia Countdown — Your next shot at winning big

by My News Wave
31 May 2025
0

TechCrunch Sessions: AI at UC Berkeley On June 5, TechCrunch Sessions: AI will take place at Zellerbach Hall, UC Berkeley, marking the third day of AI trivia events. Participants have the opportunity to demonstrate their AI knowledge by answering a series of trivia questions. By doing so, they stand a chance to win two tickets, making this an exciting occasion for AI enthusiasts. Full Article

Read more
Playdate Season Two, Spray Paint Simulator and other new indie games worth checking out
Technology

Playdate Season Two, Spray Paint Simulator and other new indie games worth checking out

by My News Wave
31 May 2025
0

The indie gaming scene continues to thrive with exciting new releases and showcases like Thinky Direct, which featured intriguing titles such as He Who Watches and Echo Weaver. Playdate Season Two has kicked off with two new games each week, including Dig! Dig! Dino! and Fulcrum Defender, while Trails offers a charming puzzle experience on Steam. As Summer Game Fest approaches, gamers can look forward to extensive coverage of new announcements and hands-on experiences with...

Read more
U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation
Technology

U.S. DoJ Seizes 4 Domains Supporting Cybercrime Crypting Services in Global Operation

by My News Wave
31 May 2025
0

A multinational law enforcement operation has successfully dismantled an online cybercrime syndicate that provided services to threat actors, enabling their malicious software to evade detection by security software. On May 27, 2025, the U.S. Department of Justice (DoJ) announced the seizure of four domains and their associated servers that facilitated this crypting service. This operation highlights the ongoing efforts to combat cybercrime and enhance digital security measures globally. Full Article

Read more
News Wave

News Summarized. Time Saved. Bite-sized news briefs for busy people. No fluff, just facts.

CATEGORIES

  • Africa
  • Asia Pacific
  • Australia
  • Business
  • Canada
  • Entertainment
  • Europe
  • India
  • Middle East
  • New Zealand
  • Sports
  • Technology
  • UK
  • USA
  • World

LATEST NEWS STORIES

  • 75% of Workers Today Plan to Have a Job in Retirement. Here's Why You Should, Too.
  • Illegal Israeli settlers establish new outpost on ruins of demolished Palestinian home in south Hebron – Middle East Monitor
  • Why people on protein-heavy diets need to eat more fiber
  • About Us
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2025 News Wave
News Wave is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology

Copyright © 2025 News Wave
News Wave is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In