Beware of new scams: GitHub project templates hide malicious code to steal Crypto Assets Private Key

robot
Abstract generation in progress

[Chain News] PANews, July 28th news, according to a certain website, a user named evada recently posted that during the job application process, they were required to use a GitHub project template designated by the employer to develop a page, only to find that the project contained malicious code. The specific manifestation is that the logo.png file in the project appears to be an image, but actually contains executable code, which is triggered through the config-overrides.js file, intending to steal the user's local Crypto Assets Private Key.

Evada pointed out that the malicious code sends requests to specific URLs, downloads trojan files, and sets them to run at startup, demonstrating high concealment and harmfulness. The website administrator claimed that the involved accounts have been banned, and GitHub has also deleted the related malicious repositories. Several users commented that this new type of scam targeting programmers is highly misleading, reminding developers to be vigilant when running projects from unknown sources.

PNG-0.8%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Repost
  • Share
Comment
0/400
FloorPriceWatchervip
· 07-30 05:18
It makes me want to curse; freeloaders really know how to take advantage.
View OriginalReply0
DefiPlaybookvip
· 07-28 10:03
According to statistics, the loss percentage of such attack paths can be as high as 23.4%.
View OriginalReply0
OnChainArchaeologistvip
· 07-28 00:12
Ha, using such methods to fool the suckers.
View OriginalReply0
CryptoGoldminevip
· 07-28 00:07
Looking at the data, more than 50% of the repositories may have risks, and developers should learn to use tools to analyze code data flows.
View OriginalReply0
JustHereForAirdropsvip
· 07-27 23:53
Don't pay too much attention to the project source code; if the Private Key is leaked, you're done.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)