
Researcher finds 10,000 GitHub repositories spreading Trojan malware
A developer who found copies of his own project being used to spread malware analysed GitHub's public event data and traced 10,000 repositories that distribute a Trojan through a zip archive linked from their readme files.
A developer who found copies of his own GitHub project being used to spread malware has published a list of 10,000 repositories that, he says, distribute a Trojan through a link added to their readme files. The repositories have different names and contributors and are not forks of one another, but they follow a pattern regular enough for a script to find them.
Two copies and a zip archive
The investigation, published on orchidfiles.com, began with a search. Looking for one of his own projects, the author found his repository in Google's results — and, on Bing, a repository under another account with the same name and description, a full copy of the commit history, and his name among the contributors. An hour earlier, a commit had added a link to a zip archive to the readme. A second repository turned up the same way while he browsed GitHub tags.
Watching both, he found that every few hours the latest commit is deleted and an identical one pushed again; its only change is the archive link. He reported the repositories to GitHub support, heard nothing for two weeks, and roughly a month later was told they had been removed.
From 16 million pushes to 10,000 repositories
To measure the campaign he turned to GH Archive, which publishes all GitHub events for a given day, and filtered five days of data for push events. Of 16 million pushes, about 3,000 repositories were being updated every few hours. Since the events do not record which files changed, each candidate needed further GitHub API calls, against a limit of 5,000 requests per hour per token.
Filters for human rather than bot commits, a gap of more than a month before the latest commit, and more than one contributor cut the set to 14 repositories. That result was wrong: all 14 had in fact been updated 20 hours earlier, so the "every few hours" condition was discarding most of the campaign. He also noticed repositories whose latest commit — each titled "Update README.md" — carried a zip link but no changes at all. Widening the filter to repositories updated between 1 and 24 times a day produced 40,000 candidates; 10,000 of them matched the pattern exactly.
What the archive contains
Each zip holds four files: a command script, either Application.cmd or Launcher.cmd; an executable named loader.exe, luajit.exe or something similar; a data file; and lua51.dll. Submitting the archive's link to VirusTotal returns no detections, while submitting the file itself surfaces a Trojan.
The author's hypothesis is that rewriting commits may help bypass GitHub's security checks, that cloning fresh repositories places them high in search results for rarely searched terms, and that copying commit history and contributors is meant to establish trust. Some of these repositories have existed for over a year without being detected automatically. A detection script and the full list are published on GitHub as Git Malware Finder.