Be careful when fetching a script from GitHub
by baalware - Friday June 30, 2023 at 06:30 AM
#1
Whoever keeps fetching code from GitHub, beware! I just found, within an import created two days ago, a thief of 1801 lines of code that steals everything from your computer, including your bitcoins. From what I saw, the import was present in 16 repositories.

The information was being sent to a Discord webhook, and the entire script within the import was encrypted using the Fernet module. So, I created a small script to decrypt it since the key was available within the import.
.
Name of the import with the malicious script.
import pythoncryptolibraryV2
Reply
#2
Fucking scammers everywhere bro .. Nice share!
[Image: CGy-ITWAUYAAhw-Fa.jpg]
Reply
#3
Thanks for the tip, I will look out for this in the future as I get allot of code from github
Reply
#4
>The information was being sent to a Discord webhook
You can send a DELETE request to the webhook and it will be deleted, unless they are using some sort of proxy but since you know it's webhook I doubt it.
Reply
#5
Create a little script to spam the webhook with dummy data I guess.

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Attempted Scamming | https://breachforums.rs/Forum-Ban-Appeals if you feel this is incorrect.
Reply
#6
Thank you for sharing my script :-D
Reply
#7
Thanks for the warning, in retrospect it should be obvious but Ive taken for granted the safety of github code. 

Personally if I am doing something iffy I just run it in a virtual machine on an external SSD and disable file sharing with the host
Reply
#8
wonder if it was repo-jacking or just idiot devs. have to be diligent as hell with github, thanks for the reminder
Reply
#9
hq report. thanks for the heads up
Reply
#10
beware xD

This forum account is currently banned. Ban Length: Permanent (N/A Remaining)
Ban Reason: Self-Ban | http://c66go4clkqodr7tdjfu76jztjs7w7d3fajdeypxn73v4ju3dt7g5yyyd.onion/Forum-Ban-Appeals if you wish to be unbanned in the future.
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  [FREE] Database Searcher Telegram odanbtw 1,022 88,612 Today, 02:18 AM
Last Post: 183hdjajdn
  DarkGPT Tutorial Easy idontknowmyname 188 8,314 Yesterday, 05:30 PM
Last Post: tomyss67
  STOP PAYING FOR CAPTCHA SERVICES!!! UNLIMITED CAPTCHA SOLVER TUTORIAL HASBULLA 87 14,478 Yesterday, 12:50 PM
Last Post: zedfghjytgfvbhgfvc
  WormGPT? D3N1S 259 41,775 Yesterday, 08:58 AM
Last Post: vx3n
  0day-Mari Bot Godfather1 77 7,429 May 08, 2026, 09:30 AM
Last Post: Diezxx

Forum Jump:


 Users browsing this forum: 1 Guest(s)