Switch language한국어
Back to the list

Hackers are using fake coding jobs to spread malware through GitHub

TL;DR AI

Key summary

2 min read
  1. Investigators have named the malware Omnistealer.

  2. Its initial code contacts the TRON or Aptos blockchains, reads hidden data that points to Binance Smart Chain, which delivers more code and the final malicious payload that activates the info‑stealer.

  3. It can target more than 10 password managers (including LastPass), over 60 crypto wallet extensions (including MetaMask and Coinbase), 10+ browsers such as Chrome and Firefox, and cloud services like Google Drive.

  4. Researchers have tied around 300,000 stolen credentials to the operation, including data from cybersecurity firms, defense companies, and government agencies in countries such as the US and Bangladesh.

  5. Attackers begin with developers and contractors to reach high‑value environments; researchers observed recurring scam roles (recruiters/intermediaries and freelance developers) and small tasks sent over LinkedIn asking to run or fix a code snippet.

Read the original