19 ms·
Github scam investigation: Thousands of “mods” and “cracks” stealing data
- dcow 2y agoWhy should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
- BoredPositron 2y agoOnly if they disguise as non malware I guess?
- episteme 2y ago> would be distributed some other way if GH removed them Maybe? But definitely to less people? I don't see the argument for allowing them.
- Cthulhu_ 2y agoDoesn't distributing malware break a number of laws?
- yuppiepuppie 2y agoWhat is the definition of distribution? If I posted a code snippet of malware on github or my personal site for educational purposes, does that count as distribution?
- creshal 2y agoThat depends heavily on the law in question. Germany e.g. almost completely bans white hat activities because hacking is evil, and no amount of common sense has been able to get through lawmakers' thick skulls.
- martin_a 2y agoYou can downvote him all you want, but it's true at the core. §202c of the BGB heavily limits what can be done, even by legit researchers, and it's often being critized for that reason. For anyone interested, the Wikipedia article might give an overview (only available in German right now): https://de.wikipedia.org/wiki/Vorbereiten_des_Aussp%C3%A4hens_und_Abfangens_von_Daten https://de.wikipedia.org/wiki/Vorbereiten_des_Aussp%C3%A4hen...
- diffeomorphism 2y agoReally? The malware went from your computer to someone else's and your defense is that it was not "distributed" but just magically moved from A to B? If you argued that it was clearly labeled as malware for educational purposes, that seems fine. It was distributed, but then distribution is allowed. But this is very clearly not the case here.
- sim7c00 2y agototally depends on where u live. id say 99% of places, u wont. also, research purposes is ok if its obvious. u can download malware in lots of places, sources, so taking them off of github really wont do anything either. personally if i post such things i will either ensure it has detections everywhere or somehow neuter it. usually for research you dont really need to have fully functioning malware. just enough to prove some question. so despite posting sources of malware being ok, and it being available in lots of places, i do think, especially for advanced things, its better not to contribute it freely... but to each their own. i'd advise strongly against just outright posting functional cyber weapons, not because its illegal, but simply because its really not needed. there is more bad potential than positive use compared to broken or incomplete versions.
- jillesvangurp 2y agoThere is an official policy on this: https://docs.github.com/en/site-policy/acceptable-use-policies/github-active-malware-or-exploits https://docs.github.com/en/site-policy/acceptable-use-polici... So, sounds like the Github team should take some action here.
- qwertox 2y agoMaybe a special flag with a passcode which must be passed to `git clone`, where this passcode is shown in such a banner. To make sure you've read the banner.
- petesergeant 2y ago> The repos aren't themselves doing harm Yes they are, they're distributing malware > are valuable for research Marginally, at best > and would be distributed some other way if GH removed them Another way that wasn't so well SEO-optimized and didn't carry the Github halo.
- timsh 2y agoI don't think that repositories presented and named as Malware or Virus should be deleted - they're good for educational and research purposes I guess. I specifically mean those that impersonate as legit programs (if you can call a "free download" or "mod" apps legit).
- aqueueaqueue 2y agoGood point instead of deleting, treat it like an invalid https cert. Lots of warnings and are you sures before you get to clone or fork.
- ale42 2y agoTo me those repos seems an abuse of what GitHub is for. I'm 100% fine with a repo hosting malware if it's there for security researchers and anybody else interested in the topic to study, etc. Even better if there is also documentation. I'm not fine with using GitHub (or any other site) as a distribution platform for malware, hiding the fact that the software is malicious in the first point.
- Retr0id 2y agoThey're just as useful for research as the spam/scam comments you occasionally see at the bottom of an HN thread.
- sgc 2y agoThese repos are targeting kids. They should be removed or at least disabled.
- otikik 2y ago> The repos aren't themselves doing harm, Yes they are. They are being used as delivery mechanism for malware.
- Aurornis 2y ago> The repos aren't themselves doing harm, Yes they are. Did you read the part about the people doing this and getting 50-100 compromised computers per day? They’re stealing accounts and crypto with these. > are valuable for research, Research into how they’re harming people? The research is done. Time to move to fixing it. > and would be distributed some other way if GH removed them. This is like saying we shouldn’t wear seatbelts because some people will still die in car crashes anyway. You don’t avoid improving a situation just because you can’t perfectly fix it globally. You address what you can and reduce the problem.
- dcow 2y agoAt least the malware is exposed in the light of day. I didn't say don’t fix something. I asked whether the malware should be removed vs e.g. being flagged by github. If github removes it, it will move somewhere else and be harder to keep a thumb on. That’s fine, I was curious because this “research” wouldn’t have happened in the first place if the malware was elsewhere. It sounds like intent here matters…
- Aurornis 2y ago> If github removes it, it will move somewhere else and be harder to keep a thumb on. It’s on GitHub for visibility and credibility to victims. If it moves somewhere else where victims can find it, the researchers can find it too.
- Fokamul 2y agoOoh, these types of malwares are very old. Most fun you can have is to generate real-like looking data (there are tools for that) and mass send them to these discord webhooks. ;-)
- L-four 2y agoAn unscrupulous individual might even send malware.
- klaas- 2y agoI think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-ec11-b6e6-000d3a4f0f1c https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...
- kennysoona 2y agoThere used to be some sort of forum they had, I don't remember what it was, MSDN forums or Technet or something, but it used to dominate search results, and all the answers were from like, senior hobbyists who couldn't suggest much more than restarting or suggesting checking for updates. Maybe that was before every search result was Reddit or SO though.
- Galanwe 2y agoThat's MSDN, and these "senior hobbyists" were given a badge by MS to look credible: "MVP" (most valuable professional). Cherry on top: you used to pay to have an MSDN membership and access this wonderful community. To be fair though, the early MSDN was really good, and in a distant past MVP was a real achievement (say early 2000s). Now it's a weird mix real issues and "my printer blinks red, how to fix?" I don't think anyone reads MSDN at Microsoft anymore, it's a deadland, but I guess they generate some metrics of user engagement and product feedback from there.
- kennysoona 2y agoI wasn't even talking about people who paid for a cert, just people signing up to try and help. They are generally more annoying then helpful to people who can do anything more than install and uninstall programs. Without a doubt every search result I found on that forum from someone having a similar issue never resulted in a useful lead.
- wil421 2y ago
- nottorp 2y ago"Or why you should never download game mods"... Like everything else, you shouldn't blindly search on github - or any other download site. Only download from links referred from the official site if there's any, or the game's forum, or any other trustable and human reviewed source.
- babygsmallz 2y agoBest part is people downloading them and turning EVERYTHING off - running it as admin, antivirus off, everything. How can you trust something random off the internet that much?
- nottorp 2y agoNot random, but let's take this example: https://forums.beamdog.com/discussion/87952/icewind-dale-2-enhanced-edition-is-released https://forums.beamdog.com/discussion/87952/icewind-dale-2-e... There is no official Enhanced Edition for IWD2 and there will never be because the source code is lost. This is a fan made mod that patches the original binaries in memory to add stuff like wide screen support etc. And it triggers your anti virus because of that. It's perfectly fine as long as you download it from the official sources.
- sylware 2y ago[flagged]
- gsck 2y agoGurn up, its 2025. Webpages have Javascript, get used to it. Run an adblocker if you care so much about it phoning home. And XHTML? The standard who's own governing body abandoned, why would anyone use that?
- sylware 2y ago[flagged]
- avodonosov 2y agoIs there such a right hosting, with noscript and basic html?
- sylware 2y agoYes. I use at least 2 of them... repo.or.cz, or rocketgit, and I guess they are many more. Drop microsoft github and move there or similar. But the best is to host yourself. But careful, you are going against big tech interests, expect their shadow-paid hackers to attack you and any real-life alternative you use.
- Thorrez 2y ago
- KomoD 2y agoFun fact: if you come across one of these discord webhooks you can delete them. Just curl -X DELETE https://discord.com/api/webhooks/ https://discord.com/api/webhooks/[...]
- Etheryte 2y agoI'm not familiar with the context here, could you please elaborate? If I understood correctly, any unauthenticated user can delete the webhook? I can currently find hundreds of matches for that on Github, anyone could just go and delete them all?
- jeroenhd 2y agoIn many cases the necessary authentication string is present within the webhook URL itself (which you're supposed to keep secret). By possessing the URL, you've proven you're authorized to use it, and with Discord that also means you're authorized to remove it. In other cases you may need additional headers to authenticate, but if the script you've found contains the URL, it probably also contains the auth header too.
- KomoD 2y agoYep, anyone can delete a Discord webhook if they have the URL. All you do is send a DELETE request to the URL.
- Thorrez 2y agoInteresting. Looks like this specific one has already been deleted: curl -X DELETE https://discord.com/api/webhooks/1050437982584324138/VJByvmBKESSUv4fYn0LIjlBR4VzMRTEPOKVJoWFvCeHd7o3LtclQMJDMuiLzT57iqn7B {"message": "Unknown Webhook", "code": 10015}
- jeffhuys 2y agoLOL okay going to write a little search&destroy script tonight. Actually, no, f microsoft, let them do it.
- cl3misch 2y ago
- _7acn 2y agoIn my opinion, Microsoft’s entire support is at a tragically poor and hopeless level. GitHub is flooded with open issues that remain open for years without any response from Microsoft. The same applies to Azure. The technical support there is also truly terrible, and it’s easy to find horror stories online about people losing access to their accounts and being unable to restore them.
- ValdikSS 2y agoWhen GoodbyeDPI malware was spreading using the similar template (lots of forked repos with password-protected archives), Github abuse team have instantly deleted it upon my request. Mean response time was 10-15 minutes. I also deleted files on the file sharing websites, such as mediafire and mega. My abuse emails followed the clear and understandable email template: your service is hosting malware, here's the link, it's password protected and the password is X, here are virustotal results, here's the original repo which it impersonates, and I want you to delete it.
- ValdikSS 2y agoHowever I remembered reporting the exact "cheats/cracks" from the post as well, and the response time was up to 5 days.
- Hilift 2y agoA bit late, but there was a bug in the GitHub Win32 OpenSSH that was introduced in last October 2024 cumulative update. This was precipitated by a PR from September 2023. It performs a permissions check on the logs and other folders, and apparently enforces the permissions it expects, as the service crashes/does not start. This seems to affect Windows platforms more as opening an affected location in Windows Explorer probably prompts the user that access is denied, and would you like to update the permissions. https://github.com/PowerShell/Win32-OpenSSH/issues/2282 https://github.com/PowerShell/Win32-OpenSSH/issues/2282
- neuroelectron 2y agoIs it really a problem to host malware on github?
- Thorrez 2y agoIf you claim in the repo description that it's not malware in order to trick people into downloading it, then definitely yes.
- aerzen 2y agoI think the core of problem here is that applications are not isolated on the OS level. If I download and install a mod for minecraft, it should never have access to anything on my computer, except for the minecraft game files itself. If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files. Something similar to how android works, were the app has to explicitly ask the user to access their files.
- kevindamm 2y agoYou're describing Qubes, which is great but I found it tedious to use as a daily driver.
- literalAardvark 2y agoThe other general purpose sandboxes are just as valid. Which is why all modern OS are moving towards them ( apk, appx, whatever OSX does) Yes, qubes is harder, but it's also very niche, barely supported, and difficult to use. There's really a lot of middle ground "any application can do whatever on your system as the user running it" and "any application runs in a separate OS with no rights and just 120 lines of hardened hypervisor code in common.
- pixl97 2y ago>If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files. So ya, you've just broken a thousand enterprise application and integrations.
- t_believ-er873 2y agoIf you've identified GitHub repositories hosting malware, you can report them directly to GitHub via their Abuse Report page, providing links and any relevant details. GitHub typically removes repositories that violate their Acceptable Use Policy, but response times may vary. If the malware is actively being used for harm, you may also consider reporting it to security organizations or CERT teams.
- nubinetwork 2y ago> response times may vary Waiting six months for Github to remove malicious repositories is unacceptable.
- jeroenhd 2y agoOne thing I appreciate about Github is that every time I've reported something, I've felt like an actual human went through my report and actually read the things I wrote. Perhaps it's a bit silly to appreciate basic human interaction, but for so many online environments the only interaction you'll ever see is done through chatbots and automated work flows.
- proactivesvcs 2y agoI may have missed the part where the author reported these to github but they're not going to be removed it nobody actually reports them. What a lot of effort put in to seemingly give up at a crucial final step.
- shawabawa3 2y agopretty sure this is an LLM generated comment
- neutralx 2y agoFirst image in the article reminds me of draw.io diagrams. Is this a drawio theme/library or some other tool was used to create it?
- philipwhiuk 2y agohttps://excalidraw.com/ https://excalidraw.com/ probably
- croisillon 2y agothe font seems to be Excalifont indeed
- neutralx 2y agoYep that looks like it. I also found that drawio indeed supports sketch theme: sketch.diagrams.net
- teddyh 2y agoIf there is no malware allowed on GitHub, I guess malware researchers have to use somewhere else to host their code. Which would be a preferable outcome, honestly.
- nomilk 2y agoWe could make an open source database. Then very simple browser extension to place a very prominent warning on any GitHub repo page that happens to be suspected malware. I guess the problem is that only helps those who already know they need to watch out for this sort of thing, not the users most likely to be pwned.
- avodonosov 2y agoLets do it.
- jbverschoor 2y agoJust don't allow direct downloads or clones. It will solve a lot, although not many.
- avodonosov 2y agoJust deleting them is not so useful. It would be better to uncover the people behind them and who use the collected data. Some honeypot scheme or social engeneering against them. Ideas?
- tomaytotomato 2y agoI must admit, sometimes reading gists and other repos on fixing hardware issues I think, "am I downloading malware?". Better to have an attitude that Github is malware and a healthy skepticism of any repo?
- linwangg 2y agoThis raises a big question: How effective is GitHub’s abuse reporting system against large-scale malware campaigns? If 1,000+ malicious repos can persist for months, does this mean GitHub lacks automated scanning or relies too much on user reports?
- EVa5I7bHFq9mnYK 2y agoAutomated scanning is easily bypassed - just fine-tune the submission until it passes the checks.
- david_allison 2y agoInsufficient. Reporting is a fairly manual process, has UX issues which discourage reporting, and is heavily rate limited. Response times can very from hours to what feels like months, and they rarely handle reports based on patterns of abuse.
- arp242 2y agoThe abuse reporting on GitHub completely sucks. You need to send a support ticket, which typically takes more than a month to get a reply to. And if by that time the comment or repo has been deleted they'll say "well it's deleted now, so we can't do anything". Because yes, I'm going to let spam sit around for over a month on my repo... :-/
- Evidlo 2y agoCan't you just report it and hide it?
- Jimmc414 2y ago> If 1,000+ malicious repos can persist for months 3 years unfortunately https://github.com/Jalynn0922/steal-cook https://github.com/Jalynn0922/steal-cook
- andrewchilds 2y agoI mean, do a search for "steal cookie": https://github.com/search?q=steal+cookie&type=repositories https://github.com/search?q=steal+cookie&type=repositories This one has been up for two years: https://github.com/Aker490/Steal-Cookie-Roblox https://github.com/Aker490/Steal-Cookie-Roblox It would be good to hear an official response from GitHub on where the boundaries are, since it seems like there's plenty of examples of clearly malicious repos hosted for years.
- avodonosov 2y agoSome time ago i was asked to help installing a mode for Plants vs. Zombies - a PVZ Fusion mode. When searching for it I found multiple, some had download from github repos. None was looking trustworthy enough, so I didnt download any. But I hesitated a little. From how they looked, I think now that was the kind of malware the author describes.
- Aurornis 2y agoThese repos post to Discord webhooks to notify of newly compromised systems. I’ve found Discord to be responsive to abuse complaints in the past. If someone wrote a simple script to download these repos and extract the Discord webhook links I bet you could get Discord to shut down their accounts. In my past experience Discord was aggressive about this, going so far as to ban the accounts of people who had participated on those servers with clearly illegal purposes. They’ll come back and make new accounts again, of course, but having them lose all of their connected servers, history, and requiring them to update every single one of their malware drops should slow them down considerably.
- avodonosov 2y ago> going so far as to ban the accounts The responsible thing would be also to release all related data, icluding personal information (IP adresses, emails, list of contacts, chat logs) to investigation (police, etc)
- anoncow 2y agoWe could lock such repos. No access (not even read-only) and disable accounts. That could also be semi automatic.
- Aurornis 2y agoI’m sure they report serious crimes and at least retain records for questionable activity. I don’t get visibility into internal Discord operations, though. We just see that the perpetrators lost both their Discord server and their accounts disappeared from other Discords they were in. They angrily returned later with new usernames.
- avodonosov 2y ago> I’m sure they report serious crimes and at least retain records for questionable activity. Why are you sure? I really doubt it.
- Avamander 2y ago
- nisten 2y agoNo
- nisten 2y agoNo? Maybe could stop people from being able to git pull them without a confirmation, but deleting does not make sense
- Thorrez 2y ago>Yes, Redox creates and starts sqlite to gather all the data in a good-looking way. Is that saying it creates a sqlite database? I kind of doubt it. I think more likely is it uses sqlite to read from existing sqlite databases that exist on disk, to steal data from them.
- vegadw 2y agoI think to an extent Microsoft is the guilty party here. For may cracks Windows Defender will trip saying "Win32/Keygen" even if there's no actual malware https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=HackTool:Win32/Keygen https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo... This trains people that do a lot of piracy to be used to turning off their antivirus to let something through, which is fine until it's not. It's like drugs, if we know a subset of the population will do them no matter what, we should make it safe for them to the extent we can. False positives, causing people to ignore actual positives, creates a market for these things.
- Aurornis 2y agoBundling malware with keygens is a very common practice. It helps because the victim doesn’t suspect anything is wrong when the thing they downloaded appears to work, unlike the sham downloads in the linked article. Gives the attackers more time to exploit the system. You also need to look at the bigger picture: Keygens are something you very much do not want anywhere in a corporate environment for obvious reasons. Being able to flag them on Windows machines is very valuable.
- catsma21 2y agosome brands put cocaine in soda, let's ban soda altogether
- vegadw 2y agoThen make it a flag for windows machines on a domain account or otherwise set to be a "business PC". Doing it on consumer systems is still a problem. A false positive flag for malware - or calling any keygen malware - is still a problem. It sholudn't be removing keygens from the system because they're keygens. You shouldn't have to add exceptions for them. If they actually contain malware, great, yes, please flag them. If they're not and it's my personal computer, then if I choose to download some cars, that's none of their business.
- landr0id 2y agoWindows Defender believes that my Rust egui application is a trojan, but magically if I compile it with a different toolchain it's no longer flagged :p There's something seriously wrong with A/V heuristics.
- andypiper 2y agoI've been reporting these repos forever, they just keep on coming.
- extraduder_ire 2y ago> Less then 10% of them have open issues with complaints - others look just fine. I don't know why anyone running one of these schemes to distribute malware would even enable the issues tab on github, let alone not delete every issue posted containing keywords like malware, trojan, virus, etc. with a script. Are hidden until approved issues not supported on github? Is this caused by some limitation of creating these repos programmatically?
- Aurornis 2y agoThese people are following a guide. They don’t know the details of GitHub. They don’t care about people who know enough to check the issues. They’re fishing for the people who blindly download and run things, not who look under the hood.
- extraduder_ire 2y agoGood point. I hadn't considered it might be intentional, like spam emails using poor grammar and appearing more scammy to select for easier marks.
- miunau 2y agonpm is full of this shit too, eg. https://www.npmjs.com/package/openssl-node https://www.npmjs.com/package/openssl-node which I reported weeks ago but is still sitting there.
- Jimmc414 2y agoWhat's concerning is that this repository appears to be the template that much of this malware was built from: https://github.com/Jalynn0922/steal-cook https://github.com/Jalynn0922/steal-cook. This repo mentioned in the article has existed on GitHub for 3 years without being taken down. Also, I am seeing firsthand that AI is not good at detecting this stuff. Claude's main problem in a code review of one of its descendants was the unethical use of an aim-bot. edit: to clarify, my concern is about how this can exist on Github for 3 years. Thank you for compiling this and sharing your review. Great work.
- timsh 2y agoIt’s not included in the list since it’s the stealer itself - it’s not misleading, it says “stealer”/“grabber”. But yeah the fact that it’s out still there is scary
- Yeul 2y agoI always thought it was amusing that if you ask about pirating Windows or Office you get a link to GitHub. Microsoft is alright in my book. Let GitHub be free.
- numba888 2y agoThe problem is this can be anything, not just mods and cracks. That's why I keep separate laptop for banking. This may not help if hackers take over the router. But still better than nothing.