Github scam investigation: Thousands of "mods" and "cracks" stealing your data
13 hours ago
- A detailed investigation reveals a widespread scam on GitHub where thousands of repositories offer fake game mods, cracks, and software that install the Redox stealer malware.
- The malware collects victims' data including crypto wallet keys, bank accounts, social media credentials, Steam and Riot Games accounts, and sends it to a Discord server via webhook.
- The scam is promoted through a step-by-step guide on a social engineering forum, which advises creating multiple GitHub accounts, using specific topics to appear in search results, and uploading malicious archives.
- The author of the investigation wrote a script to find repositories matching the guide's patterns, uncovering 1,115 such repos, of which only 115 had open issues warning users—less than 10%.
- The Redox stealer code is obfuscated and uses techniques like base64 decoding and Discord webhooks to exfiltrate data, targeting browsers, crypto extensions, gaming platforms, and more.
- The investigation highlights the ease of access to such scam instructions on the clear web and the lack of effective detection by GitHub, despite many repos having clear malware indicators.