216.73.217.22

Clone, Compile, Compromise: Open-Source Malware Trap on GitHub

· Published 16/06/2025 13:03 · Modified 16/06/2025 15:24

Export JSON

Essential information

Published
16/06/2025 13:03
Modified
16/06/2025 15:24
Tags
2025-06-16 anti-debugging backdoor.js.dullrat data exfiltration github multistage malware open-source persistence privilege-escalation supply-chain
Related entities
1 intrusion sets (apt), 16 techniques (mitre), 1 malware

Description

A newly identified threat actor, Water Curse, is exploiting to deliver weaponized repositories containing . The group has been linked to at least 76 accounts, targeting cybersecurity professionals, game developers, and DevOps teams. Their malware enables , remote access, and long-term on infected systems. The attack begins with trojanized tools, progresses through complex infection chains using obfuscated scripts, and culminates in extensive system reconnaissance and data theft. Water Curse employs techniques, privilege escalation methods, and mechanisms to maintain control over affected systems. The campaign poses a significant supply chain risk, especially to those relying on tooling from .

External references