A proof-of-concept Windows stealer was published showing how the GitHub REST API can be abused as a command-and-control and data-exfiltration channel by posting comments to a GitHub issue. The sample uses a GitHub personal access token and WinHTTP to send data to api.github.com, specifically the issue-comments endpoint, demonstrating how attacker traffic can blend with legitimate developer-platform activity.
The malware example collects host and network details from Windows systems, including hostname, operating system, processor, drive information, IP address, subnet, and MAC address, then transmits the data through GitHub issue comments. The author demonstrated the technique on Windows 10 and Windows 11 virtual machines and observed outbound traffic to GitHub API infrastructure, underscoring how trusted cloud services can be repurposed to hide malicious communications and exfiltration.

Get the actors, campaigns, and ATT&CK mapping behind it.
1 event from the most recent confirmed update back to the earliest known activity.
A blog post presented a Windows proof-of-concept stealer written in C that abuses the GitHub REST API to post comments to a GitHub issue, first sending a test string and then exfiltrating host and network information. The demonstration included compiling and running the sample on Windows 10 and Windows 11 virtual machines and observing traffic to a GitHub API IP address.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.