Loading market data...

Kaspersky Uncovers GitVenom Malware Campaign Using Fake GitHub Projects to Steal Bitcoin

Kaspersky Uncovers GitVenom Malware Campaign Using Fake GitHub Projects to Steal Bitcoin

Kaspersky has identified a malware framework called GitVenom that uses more than 200 fake GitHub repositories to target cryptocurrency investors. The campaign relies on AI-generated documentation to make the malicious projects look legitimate. Bitcoin is the primary target, with attackers aiming to drain wallets from developers and investors who download the poisoned code.

How GitVenom works

The fake repositories mimic real open-source projects. They include README files, commit histories, and even issue trackers — all generated or copied to appear authentic. But hidden inside the code is a malware framework that, once executed, can steal wallet keys, clipboard data, and browser credentials. Kaspersky's researchers found that the AI-generated docs are convincing enough to fool even experienced developers.

The scale of the operation

Kaspersky says the campaign involves over 200 separate GitHub repositories. That's not a small operation — it's a coordinated effort to spread malware across multiple projects. The researchers didn't name specific repositories or the attackers behind them, but they noted the campaign has been active for some time. The use of AI to generate documentation is a relatively new tactic, making it harder for automated scanners to flag the repos as fake.

For anyone working with Bitcoin or other cryptocurrencies, this is a reminder that open-source code isn't always safe. The fake projects target developers who might clone a repo without checking every line. Once the malware is on a machine, it can intercept transactions and empty wallets. Kaspersky advises users to verify repository authenticity by checking the project's history, the developer's reputation, and any external links. They also recommend running code in a sandbox before using it on a live system.

The timing isn't great — crypto markets have been volatile this month, and security incidents tend to spike when people are distracted. GitVenom is the latest example of attackers adapting their methods to exploit trust in open-source ecosystems.