GitHub repositories are being attacked and wiped in new extortion scam

(Image credit: Shutterstock / fiskes)

GitHub users are falling victim to an ongoing extortion campaign that threatens to delete their data for good.

Cybersecurity researchers from CronUp have warned of a threat actor with the alias Gitloker breaking into people’s GitHub accounts, stealing the contents, and then wiping the accounts clean.

After that, the attacker would leave a note in the account, inviting the victim for a Telegram chat, where they could negotiate the return of the files, in exchange for money: "I hope this message finds you well. This is an urgent notice to inform you that your data has been compromised, and we have secured a backup," the threat actor says in the ransom note.

Securing your GitHub account

At this time, it is unknown how Gitloker managed to compromise these accounts. BleepingComputer speculates that they’re likely using credentials stolen in earlier attacks. Alternatively, they might have obtained them on the dark web.

Given its huge populairty, GitHub often faces a barrage of different cyberattacks, and users should do their part in securing their files on the platform by enabling two-factor authentication, or setting up a passkey as an alternative to a password-based login. They should review and revoke unauthorized access to SSH keys, deploy keys, and authorized integration, and should verify all email addresses associated with their account.

Finally, they should keep track of security logs and manage webhooks.

Usually, threat actors would try to smuggle malware into GitHub repositories, often by means of typosquatting. They would create a repository with a name almost identical to that of a legitimate package, and use automated bots to give it a high rating and a few solid reviews. After that, they would advertise it in coding communities and similar forums.

Besides GitHub, PyPI is another popular code repository that often struggles to contain hacking campaigns.

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
An abstract image of digital security.
Hundreds of GitHub repositories hijacked to trick users into downloading malware
A white padlock on a dark digital background.
GitHub is hiding malware disguised as games, legitimate software
Shadowed hands on a digital background reaching for a login prompt.
This worrying Git flaw could lead to users leaking credentials
Image depicting a hand on a scanner
New Lazarus Group campaign sees North Korean hackers spreading undetectable malware through GitHub and open source packages
GitHub Webpage
A cracked malicious version of a Go package lay undetected online for years
North Korean flag with a hooded hacker
North Korean hackers are posing as software development recruiters to target freelancers
Latest in Security
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
linkedin
Watch out - that LinkedIn email could be a fake, laden with malware
An American flag flying outside the US Capitol building against a blue sky
Mass federal layoffs will have “devastating impact on cybersecurity, former NSA cybersecurity director warns
A hand reaching out to touch a futuristic rendering of an AI processor.
North Korean fake job hackers are going the extra mile to make sure their scams seem legit
A hand reaching out to touch a futuristic rendering of an AI processor.
Google Cloud unveils new AI Protection security tools, no matter which model you use
A TV remote pointing at YouTube logo
YouTube warns of phishing video using its CEO as bait
Latest in News
Stock photographs of people smiling and looking at laptops in a small business environment.
This web hosting platform elevates your online presence
The Samsung Galaxy S25 Edge on display at Galaxy Unpacked
Exclusive: the Samsung Galaxy S25 Edge will have durability to match its ‘sexy’ form
Metaphor: ReFantazio
Sega was Metacritic's highest-rated publisher of 2024 thanks to the critically acclaimed Metaphor: ReFantazio and Like a Dragon: Infinite Wealth
AirPods Pro Review
Apple has quietly updated its guidance on how to clean your AirPods, and suggests you buy a kit… from Belkin
China
Chinese hackers who targeted key US infrastructure charged by Justice Department
A screen shot of Lady Gaga in her interview with Zane Lowe for Apple Music
Lady Gaga’s Spotify press conference is being live streamed today – here’s where you can watch Spotify’s big step forward in fan inclusion