GitVenom is the name Kaspersky gave to a malware-distribution campaign that used convincing but backdoored GitHub repositories to infect users, particularly developers and users seeking gaming cheats, malware projects, exploits, or cryptocurrency-related tools. Reporting cited here describes a broader cluster of at least 141 related repositories, 133 of which were backdoored, with repository activity artificially inflated through automated commits and GitHub Actions workflows named "Star" to make the projects appear actively maintained. The campaign has been associated with roughly 200 backdoored GitHub repositories in public reporting.
Observed delivery mechanisms included malicious Visual Studio PreBuild events, Python backdoors, JavaScript backdoors, and disguised screensaver (.scr) files masquerading as solution files via right-to-left override filename tricks. In one documented chain, compiling a trojanized Visual Studio project caused a VBS script to be written to the Temp directory, which then launched PowerShell to decode obfuscated staging URLs from services including rlim.com, glitch.me, Pastebin, Pastejustit, and paste.fo. These stages ultimately downloaded a password-protected archive, SearchFilter.7z, from a GitHub releases page associated with the repository unheard44/fluid_bean.
The final payload chain included an Electron-based malware component whose app.asar contained code for Telegram communications, screenshot capture, scheduled task creation, registry manipulation, Windows Defender exclusion or disabling actions, shadow copy deletion, host-information collection, and infection notification to the attacker via Telegram. Prior technical analysis referenced in the source reporting linked the downstream payloads to AsyncRAT modules, Remcos, and Lumma Stealer. Separate reporting also states the campaign stole approximately $456,000 in Bitcoin by hijacking wallets.
The activity showed recurring infrastructure and identifiers including the email address ischhfd83@rambler.ru, the hardcoded Fernet key "vibe.process-byunknown," the aliases or strings "Unknown," "unkownx," and "Muck," Telegram bot infrastructure, and malicious paste accounts such as Ali888Z. Researchers noted overlaps with previously reported GitHub malware-distribution operations and assessed possible links to a Distribution-as-a-Service ecosystem such as Stargazer Goblin or a closely related operation, but attribution remains inconclusive.
High-confidence targets mentioned in the reporting were people who compiled or ran code from these repositories, especially cheating gamers, inexperienced threat actors, developers, and curious researchers, rather than enterprise victims. Public reporting also notes the use of fake GitHub projects to hijack cryptocurrency wallets.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
5 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Malware campaign using fake GitHub projects to target gamers and crypto investors; steals cryptocurrency by hijacking wallets; associated losses reported in Bitcoin.
Name given by Kaspersky to a campaign involving numerous backdoored GitHub repositories, auto-commits, multiple backdoor variants, and payload delivery including RATs and clipboard hijackers.
The name Kaspersky gave to a related campaign involving many backdoored GitHub repositories and multiple payloads.
Malware delivery campaign using convincing malicious GitHub repositories (including inflated commit histories) to lure developers into downloading malicious scripts or libraries; researchers assessed possible AI use in repo creation.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.