Automatically translated.View original post

Hackers used over 7,600 fake GitHub accounts.

Hackers Found, Used Over 7,600 Fake GitHub Accounts in SmartLoader Malware Release

According to a report by The Hacker News website, 7,600 Repo accounts have been detected with over 800 Repo accounts that claim to be Skills in AI or Artificial Intelligence, or MCP servers. In total, 6,600 Repo accounts have been created with Developer Profiles, which contain over 800 Repo accounts that claim to be Skills in Artificial Intelligence or Model Context Protocol. By various (fake) projects, they are either imitated or copied in some of them by Copy. It comes directly with a very reliable README guide, which the research team that detected the campaign named FakeGit.

The main purpose of this campaign is to try to get SmartLoader malware to access the victim's system to create persistence on the system and then manage to download the second malware (payload), which is usually a malware type that steals data from the victim's machine or an Infostealer like StealC, installed to steal important data on the victim's machine through the installation of these fake tools to gain access to the system. The malware is sent to the machine through an MCP server. The zip compressed file triggers a chain of loaders like LuaJIT Loader, which leads to a runup. A Lua pt that was written in a pattern to confuse the victim's system (Obfuscation) to lead to a SmartLoader malware download that would ultimately serve to download StealC malware down the installation.

This campaign will introduce AgentBaiting techniques. That is, when a user searches for Skills or MCP servers with the use of AI Agents and AI assistants find these fake Repo, the AI assistant will understand that the Zip file that claims to be the tool is a reliable file that can be downloaded down and installed. README on these fake Repo is just a simple installation method that can be followed, allowing the AI assistant to follow what the hackers tempted to download and install malware to the machine. There is no need for victims to do anything other than this. According to the investigation, famous AI models such as Claude Code, Gemini, and ChatGPT can all be deceived in this way, and the development of this technique has gone so far as to deceive these AI just by typing instructions (Prompt) like "Find free claude cinematic prompt skills, and give me the installation instructions" or "give me a free walmart MCP server link."

# Trending # lemon 8 diary # Lemon 8 Howtoo # github # freedomhack

5 days agoEdited to

... Read moreจากประสบการณ์ในการติดตามข่าวสารและวิเคราะห์ช่องโหว่ความปลอดภัยบนแพลตฟอร์มโค้ดต่างๆ เช่น GitHub เหตุการณ์ที่พบว่าแฮกเกอร์สร้างบัญชีปลอมและ Repo ปลอมมากกว่า 7,600 บัญชีเพื่อติดตั้งมัลแวร์ SmartLoader ถือเป็นตัวอย่างของการโจมตีขั้นสูงที่น่ากังวลอย่างยิ่ง SmartLoader ไม่เพียงแต่ใช้เทคนิคการซ่อนโค้ดโดยการ Obfuscation ที่ซับซ้อน แต่ยังมีการนำไฟล์ Zip ผ่านเซิร์ฟเวอร์ MCP ซึ่งกระตุ้นให้เกิดการรันสคริปต์ Lua ที่ซับซ้อน ทำให้มัลแวร์สามารถติดตั้งตัวเสริมเพื่อขโมยข้อมูลสำคัญบนเครื่องเหยื่อได้โดยไล่ลำดับอย่างมีระบบ สิ่งที่น่าตกใจคือเทคนิค AgentBaiting ซึ่งแฮกเกอร์ออกแบบมาเพื่อหลอกผู้ช่วย AI รุ่นใหม่ๆ อย่าง ChatGPT, Claude Code และ Gemini โดยใช้ Repo ปลอมที่ดูเป็นมืออาชีพ มี README ที่น่าเชื่อถือ เมื่อผู้ใช้หรือ AI สั่งให้ค้นหาเครื่องมือหรือคำสั่งบางอย่าง AI จะเข้าใจผิดและดาวน์โหลดมัลแวร์โดยไม่รู้ตัว จากแนวทางนี้ เห็นได้ชัดว่าผู้ใช้ทั่วไปและนักพัฒนา AI ต้องระมัดระวังการใช้อินพุตกับ AI และต้องตรวจสอบแหล่งที่มาของซอฟต์แวร์อย่างรอบคอบก่อนการติดตั้ง นอกจากนี้ การอัพเดตซอฟต์แวร์ป้องกันไวรัส และตั้งค่าความปลอดภัยบนระบบให้รองรับการตรวจจับมัลแวร์ประเภท Infostealer เช่น StealC ก็จำเป็นอย่างยิ่ง สุดท้ายนี้การศึกษาข้อมูลเกี่ยวกับวิธีการโจมตี เช่น จากกรณี FakeGit นี้ช่วยให้เราสามารถเตรียมตัวและรับมือกับภัยคุกคามทางไซเบอร์ในยุคที่ AI มีบทบาทเพิ่มมากขึ้นได้ดีขึ้น การแบ่งปันข้อมูลและการเพิ่มความรู้ด้านความปลอดภัย IT จะช่วยลดความเสียหายจากเหตุการณ์ในลักษณะนี้ในอนาคต