banner

Shady Repository, weird warnings

Reddit user huggesh_nair reported that he was given access to a private repository on Github, where they were to download application data for the assignment. The installation failed, and subsequently the system asked permission to install a Python package (Python is a scripting language that is commonly used by developers to automate and facilitate certain tasks). Not recalling any reason why this should be happening, the user grew wary and turned to Reddit for advice. They were told that this seemed extremely suspicious, and that the best course of action was probably to reset the system. This was not bad advice, because it turns out that this assignment came with a little extra. 

Most prominently, there are a few heavily obfuscated scripts among the downloaded data from the repository. These, as it turns out, steal data from a variety of browsers. Session Tokens, stored password and crypto wallets are what those malicious scripts are after.  

banner

Converter

Source: CurrencyRate
Top Selling Multipurpose WP Theme

Newsletter

Subscribe my Newsletter for new blog posts, tips & new photos. Let's stay updated!

banner

Leave a Comment

Layer 1
Your Crypto & Blockchain Beacon

CryptoInsightful

Welcome to CryptoInsightful.com, your trusted source for in-depth analysis, news, and insights into the world of cryptocurrencies, blockchain technology, NFTs (Non-Fungible Tokens), and cybersecurity. Our mission is to empower you with the knowledge and understanding you need to navigate the rapidly evolving landscape of digital assets and emerging technologies.