Kaspersky’s Global Research and Analysis Team has uncovered a malware operation called GitVenom that weaponizes one of the most trusted platforms in software development: GitHub. The campaign planted more than 200 fake repositories disguised as legitimate open-source projects, targeting developers and cryptocurrency investors with a cocktail of info-stealers, remote access trojans, and clipboard hijackers designed to redirect crypto transactions.
How GitVenom actually works
The campaign, detailed in a Kaspersky report dated February 24, 2025, has been active since at least 2023. Its operators created repositories that looked convincingly real, complete with AI-generated README files, inflated commit histories, and code written across multiple programming languages. The goal was simple: look like a busy, credible open-source project so developers would clone the repo without a second thought.
Once a developer downloaded and built one of these projects, hidden malicious scripts would execute. The malware payloads varied but included Node.js-based info-stealers capable of harvesting personal data, browser credentials, and banking information. More advanced variants deployed open-source remote access tools like Quasar and AsyncRAT, giving attackers persistent backdoor access to infected machines.









