![]() |
|
Hacking News GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contrib - Printable Version +- (https://hackmyride.com/forum) +-- Forum: Automotive Hacking (https://hackmyride.com/forum/forumdisplay.php?fid=211) +--- Forum: News (https://hackmyride.com/forum/forumdisplay.php?fid=278) +---- Forum: The Hacker News (https://hackmyride.com/forum/forumdisplay.php?fid=279) +---- Thread: Hacking News GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contrib (/showthread.php?tid=8269) |
GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contrib - The Hacker News - 09-28-2023 GitHub Repositories Hit by Password-Stealing Commits Disguised as Dependabot Contrib A new malicious campaign has been observed hijacking GitHub accounts and committing malicious code disguised as Dependabot contributions with an aim to steal passwords from developers. "The malicious code exfiltrates the GitHub project's defined secrets to a malicious C2 server and modify any existing javascript files in the attacked project with a web-form password-stealer malware code https://thehackernews.com/2023/09/github-repositories-hit-by-password.html |