216.73.216.233

Stealthy GitHub Malware Campaign Targets Devs

· Published 19/06/2025 22:30 · Modified 23/06/2025 23:01

Export JSON

Essential information

Published
19/06/2025 22:30
Modified
23/06/2025 23:01
Tags
2025-06-19 backdoor encoding github open-source python repositories supply-chain trojanized files
Related entities
2 observables, 1 intrusion sets (apt), 8 techniques (mitre), 1 others

Description

A new campaign exploiting to distribute malicious code disguised as legitimate hacking tools has been uncovered. The operation, attributed to the group known as Banana Squad, used 67 hosting that mimicked benign projects. The attackers exploited 's interface to conceal code using long space strings, making the malicious content invisible in normal view. Each account typically hosted one repository, likely fake and created solely to deliver malicious content. Hidden code within the files used methods to obscure payload delivery functions. The campaign reflects a shift in software supply chain attacks, with attackers now leveraging more covert tactics to target platforms like . Developers are advised to verify , avoid reliance on single-repository accounts, and monitor for suspicious domains.

External references