
Kaspersky uncovered GitVenom, a campaign using 200+ fake GitHub repos with AI docs to plant clipboard clippers and info-stealers. One victim lost 5 BTC ($485K).
Kaspersky's Global Research and Analysis Team uncovered a malware operation, dubbed GitVenom, that weaponized GitHub to steal cryptocurrency and credentials from developers and investors. The campaign planted more than 200 fake repositories disguised as legitimate open-source projects, complete with AI-generated README files and inflated commit histories to appear credible.
Once a developer cloned and built a project, hidden scripts executed. The payloads included Node.js info-stealers that harvested browser credentials and banking data, plus remote access trojans such as Quasar and AsyncRAT that gave attackers persistent backdoor access, Kaspersky said in a report dated February 24, 2025.
The most dangerous component for crypto holders was a clipboard clipper. It monitors the user's clipboard for cryptocurrency wallet addresses and silently swaps in the attacker's address. The victim copies what they think is their own address, pastes it into a transaction, and sends funds to the thieves.
Kaspersky flagged a single transaction in November 2024 where approximately 5 BTC, worth roughly $485,000 at the time, was transferred to a wallet controlled by the attackers. Infections have been detected globally, with notable concentrations in Russia, Brazil, and Turkey.
For individual investors, the immediate fix is to verify wallet addresses character by character before confirming a transaction. A hardware wallet that displays the destination address on its own screen provides an extra layer of verification that software alone cannot match, the researchers noted.
The campaign has been active since at least 2023. GitVenom's operators created repositories that looked busy and credible, writing code across multiple programming languages. The goal was to make developers clone the repo without a second thought, Kaspersky said.
For developers, supply chain attacks like GitVenom exploit dependency on third-party code by hiding malicious functionality inside seemingly useful libraries. As long as open-source code sharing remains a cornerstone of development, threat actors will continue to use it as a distribution channel, the researchers said.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.