Hasty Briefsbeta

Bilingual

Github scam investigation: Thousands of "mods" and "cracks" stealing your data

13 hours ago
  • A detailed investigation reveals a widespread scam on GitHub where thousands of repositories offer fake game mods, cracks, and software that install the Redox stealer malware.
  • The malware collects victims' data including crypto wallet keys, bank accounts, social media credentials, Steam and Riot Games accounts, and sends it to a Discord server via webhook.
  • The scam is promoted through a step-by-step guide on a social engineering forum, which advises creating multiple GitHub accounts, using specific topics to appear in search results, and uploading malicious archives.
  • The author of the investigation wrote a script to find repositories matching the guide's patterns, uncovering 1,115 such repos, of which only 115 had open issues warning users—less than 10%.
  • The Redox stealer code is obfuscated and uses techniques like base64 decoding and Discord webhooks to exfiltrate data, targeting browsers, crypto extensions, gaming platforms, and more.
  • The investigation highlights the ease of access to such scam instructions on the clear web and the lack of effective detection by GitHub, despite many repos having clear malware indicators.