- Kaspersky found a new malicious campaign that took advantage of sourceforge
- The campaign distributed a cryptomins and a clipboard jackets
- SourceForge said the attack was quickly stopped
Hackers tried to use SourceForge to distribute malware, but thanks to the rapid reaction of the platform, it seems that important escalation has been averted.
Earlier this month, security researchers Kaspersky said they discovered a “rather unique” malware -distribution scheme, where a fake Microsoft Office project, called ‘Officepackage’, was uploaded to the main site sourceforge.net.
Officepackage was advertised as a collection of Microsoft Office add-on development tools. Its description and files are a copy of the legitimate Microsoft project ‘Office-Addin scripts’, it was said, which can be found at GitHub.
“No malicious files hosted”
In reality, the files act like a malware dropper, a cryptocurrency and a clipboard. Kaspersky said the threat actors can use the files implemented through the project to drop additional malware on compromised final points or to use their computer power to my cryptocurrencies. Furthermore, the files keep track of the clipboard for copied crypto addresses and replace them with those belonging to the striker on pasta.
For those who are not aware of SourceForge, it is a popular site that hosts Open Source software projects and provides hosting, comparison and distribution services.
Kaspersky said that before they were drawn, they infected 4,604 systems, most of which are in Russia.
SourceForge on the other hand says its platform had not broken in: “There were no malicious files hosted at SourceForge, and there were no violations of any kind,” the project’s president, Logan Abbott, said in a written statement shared with bleeping computer.
“The malicious actor and the project in question were removed almost immediately after it was discovered. All files on sourceforge.net (the main site, not the project’s site under doms) are scanned to malware, and this is where users have to download files from. Whatever we have put additional protections in place, so project site that uses free web hosting, cannot link to external -Emrigations in the future. “
Via Bleeping computer