{"id":142561,"date":"2025-02-26T17:14:48","date_gmt":"2025-02-26T17:14:48","guid":{"rendered":"https:\/\/cryptonews.com\/br\/?p=142561"},"modified":"2025-02-26T17:14:48","modified_gmt":"2025-02-26T17:14:48","slug":"pesquisadores-da-kaspersky-identificam-ataque-no-github","status":"publish","type":"post","link":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/","title":{"rendered":"Pesquisadores da Kaspersky identificam ataque no GitHub visando carteiras de criptomoedas"},"content":{"rendered":"<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1472\" height=\"983\" src=\"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg\" alt=\"github\" class=\"wp-image-105638\" srcset=\"https:\/\/cryptonews.com\/br\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg 1472w, https:\/\/cryptonews.com\/br\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking-300x200.jpeg 300w, https:\/\/cryptonews.com\/br\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking-1024x684.jpeg 1024w, https:\/\/cryptonews.com\/br\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking-768x513.jpeg 768w\" sizes=\"auto, (max-width: 1472px) 100vw, 1472px\"><\/figure><p>Especialistas da Kaspersky descobriram um novo meio de ataque no GitHub. Em suma, os reposit\u00f3rios falsos estavam sendo usados para distribuir c\u00f3digo malicioso com o objetivo de comprometer carteiras de criptomoedas.<\/p><p>A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub. Estes estavam disfar\u00e7ados como projetos leg\u00edtimos de automa\u00e7\u00e3o para redes sociais, gerenciamento de carteiras e aprimoramento de jogos.<\/p><p>Apesar de se parecerem com <a href=\"https:\/\/cryptonews.com\/br\/criptomoedas\/wallet-anonima\/\">softwares open-source<\/a> confi\u00e1veis, esses reposit\u00f3rios n\u00e3o entregavam as funcionalidades prometidas.<\/p><p>Em vez disso, continham instru\u00e7\u00f5es ocultas para instalar bibliotecas criptogr\u00e1ficas, baixar <em>payloads<\/em> adicionais e executar scripts maliciosos, colocando em risco usu\u00e1rios que baixavam e executavam o c\u00f3digo.<\/p><p><strong>Tamb\u00e9m pode interessar: <\/strong><a href=\"https:\/\/cryptonews.com\/br\/guides\/coisas-a-saber-antes-de-comprar-bitcoin\/\"><strong>Coisas a saber antes de comprar Bitcoin<\/strong><\/a><\/p><h2 class=\"wp-block-heading\" id=\"h-malware-no-github-atinge-multiplas-linguagens\">Malware no GitHub atinge m\u00faltiplas linguagens<\/h2><span class=\"replacer\"><\/span><p>A campanha GitVenom espalha c\u00f3digo malicioso por meio de projetos escritos em Python, JavaScript, C, C++ e C#, explorando diferentes t\u00e9cnicas para comprometer os dispositivos das v\u00edtimas.<\/p><p>Nos reposit\u00f3rios Python, os atacantes utilizam uma longa sequ\u00eancia de caracteres de tabula\u00e7\u00e3o para ocultar comandos que instalam pacotes como <em>cryptography <\/em>e <em>fernet<\/em>, permitindo que o malware descriptografe e execute cargas maliciosas.<\/p><p>J\u00e1 nos projetos JavaScript, o c\u00f3digo malicioso decodifica um script Base64, ativando rotinas ocultas de ataque.<\/p><p>Em C, C++ e C#, o golpe se esconde em arquivos de projeto do Visual Studio, onde se adiciona um script em lote disfar\u00e7ado no momento da compila\u00e7\u00e3o do c\u00f3digo. Segundo a <a href=\"https:\/\/www.kaspersky.com.br\/\">Kaspersky<\/a>, cada carga executada busca novos componentes armazenados em reposit\u00f3rios controlados pelos invasores no <a href=\"https:\/\/github.com\/\">GitHub<\/a>.<\/p><p>Entre os elementos adicionais baixados pelo malware, destaca-se um stealer baseado em Node.js. Este foi projetado para roubar credenciais salvas, dados de carteiras digitais e hist\u00f3rico de navega\u00e7\u00e3o. Essas informa\u00e7\u00f5es s\u00e3o ent\u00e3o compactadas e enviadas para os atacantes via Telegram.<\/p><p>Al\u00e9m disso, os cibercriminosos utilizam ferramentas de acesso remoto open-source, como AsyncRAT e Quasar Backdoor, para assumir o controle do sistema das v\u00edtimas.<\/p><p>Por fim, tamb\u00e9m empregou-se um hijacker de \u00e1rea de transfer\u00eancia para interceptar endere\u00e7os de <a href=\"https:\/\/cryptonews.com\/br\/noticias\/tether-cria-assistente-de-carteira-de-bitcoin-baseado-em-ia\/\">carteiras cripto<\/a> e substitu\u00ed-los por carteiras sob o controle dos criminosos, desviando os fundos sem que a v\u00edtima perceba.<\/p><figure class=\"wp-block-image size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"250\" src=\"https:\/\/cimg.co\/p\/no_image.svg\" alt=\"Nos siga no Google News\" class=\"wp-image-111271 lazyload\" style=\"width:340px;height:auto\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" data-src=\"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2024\/01\/1704896093-googlenews.png\" data-srcset=\"https:\/\/cryptonews.com\/br\/wp-content\/uploads\/sites\/13\/2024\/01\/1704896093-googlenews.png 1000w, https:\/\/cryptonews.com\/br\/wp-content\/uploads\/sites\/13\/2024\/01\/1704896093-googlenews-300x75.png 300w, https:\/\/cryptonews.com\/br\/wp-content\/uploads\/sites\/13\/2024\/01\/1704896093-googlenews-768x192.png 768w\"><\/figure><h2 class=\"wp-block-heading\" id=\"h-leia-mais\">Leia mais:<\/h2><span class=\"replacer\"><\/span><ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/cryptonews.com\/br\/noticias\/blockchain-tron-domina-entradas-em-stablecoins-com-us-824-mi-em-uma-semana\/\" target=\"_blank\" rel=\"noreferrer noopener\">Blockchain Tron domina entradas em stablecoins com US$ 824 mi em uma semana<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/cryptonews.com\/br\/noticias\/operador-da-okx-se-declara-culpado-por-violacoes-de-aml\/\" target=\"_blank\" rel=\"noreferrer noopener\">Operadora da OKX admite ter violado leis de combate \u00e0 lavagem de dinheiro dos EUA<\/a><\/li>\n\n\n\n<li><a href=\"https:\/\/cryptonews.com\/br\/noticias\/binance-vai-dar-criptomoeda-de-graca-40-000-000-red-que-esta-em-70-blockchains\/\" target=\"_blank\" rel=\"noreferrer noopener\">Binance vai dar criptomoeda de gra\u00e7a: 40.000.000 RED que est\u00e1 em 70 blockchains<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Especialistas da Kaspersky descobriram um novo meio de ataque no GitHub. Em suma, os reposit\u00f3rios falsos estavam sendo usados para distribuir c\u00f3digo malicioso com o objetivo de comprometer carteiras de criptomoedas.A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub. Estes estavam disfar\u00e7ados como projetos leg\u00edtimos de automa\u00e7\u00e3o para [&hellip;]<\/p>\n","protected":false},"author":311,"featured_media":105638,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1167],"tags":[],"editores":[1187],"sponsored_companies":[],"class_list":["post-142561","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-noticias-de-defi","editores-pedro-augusto"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Kaspersky identifica ataque no GitHub visando carteiras cripto - CryptoNews Brasil<\/title>\n<meta name=\"description\" content=\"A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/\" \/>\n<meta property=\"og:locale\" content=\"pt_BR\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Kaspersky identifica ataque no GitHub visando carteiras cripto - CryptoNews Brasil\" \/>\n<meta property=\"og:description\" content=\"A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/\" \/>\n<meta property=\"og:site_name\" content=\"CryptoNews Brasil\" \/>\n<meta property=\"article:published_time\" content=\"2025-02-26T17:14:48+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1472\" \/>\n\t<meta property=\"og:image:height\" content=\"983\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:title\" content=\"Kaspersky identifica ataque no GitHub visando carteiras cripto - CryptoNews Brasil\" \/>\n<meta name=\"twitter:description\" content=\"A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub.\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg\" \/>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Kaspersky identifica ataque no GitHub visando carteiras cripto - CryptoNews Brasil","description":"A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/","og_locale":"pt_BR","og_type":"article","og_title":"Kaspersky identifica ataque no GitHub visando carteiras cripto - CryptoNews Brasil","og_description":"A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub.","og_url":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/","og_site_name":"CryptoNews Brasil","article_published_time":"2025-02-26T17:14:48+00:00","og_image":[{"width":1472,"height":983,"url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg","type":"image\/jpeg"}],"twitter_card":"summary_large_image","twitter_title":"Kaspersky identifica ataque no GitHub visando carteiras cripto - CryptoNews Brasil","twitter_description":"A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub.","twitter_image":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg","schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/#article","isPartOf":{"@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/"},"author":{"name":"Pedro Augusto","@id":"https:\/\/cryptonews.com\/br\/#\/schema\/person\/948e5928bc3628ceee2a3c1a79ecda58"},"headline":"Pesquisadores da Kaspersky identificam ataque no GitHub visando carteiras de criptomoedas","datePublished":"2025-02-26T17:14:48+00:00","mainEntityOfPage":{"@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/"},"wordCount":432,"publisher":{"@id":"https:\/\/cryptonews.com\/br\/#organization"},"image":{"@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/#primaryimage"},"thumbnailUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg","articleSection":["Not\u00edcias de DeFi"],"inLanguage":"pt-BR","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cryptonews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/","url":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/","name":"Kaspersky identifica ataque no GitHub visando carteiras cripto - CryptoNews Brasil","isPartOf":{"@id":"https:\/\/cryptonews.com\/br\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/#primaryimage"},"image":{"@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/#primaryimage"},"thumbnailUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg","datePublished":"2025-02-26T17:14:48+00:00","description":"A investiga\u00e7\u00e3o revelou uma campanha chamada GitVenom, na qual cibercriminosos criaram centenas de reposit\u00f3rios no GitHub.","breadcrumb":{"@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/#breadcrumb"},"inLanguage":"pt-BR","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/"]}],"author":[]},{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/#primaryimage","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/04\/hacking.jpeg","width":1472,"height":983},{"@type":"BreadcrumbList","@id":"https:\/\/cryptonews.com\/br\/noticias\/pesquisadores-da-kaspersky-identificam-ataque-no-github\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cryptonews.com\/br\/"},{"@type":"ListItem","position":2,"name":"Pesquisadores da Kaspersky identificam ataque no GitHub visando carteiras de criptomoedas"}]},{"@type":"WebSite","@id":"https:\/\/cryptonews.com\/br\/#website","url":"https:\/\/cryptonews.com\/br\/","name":"Cryptonews Portugal","description":"","publisher":{"@id":"https:\/\/cryptonews.com\/br\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cryptonews.com\/br\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"pt-BR"},{"@type":"Organization","@id":"https:\/\/cryptonews.com\/br\/#organization","name":"Cryptonews Portugal","url":"https:\/\/cryptonews.com\/br\/","logo":{"@type":"ImageObject","inLanguage":"pt-BR","@id":"https:\/\/cryptonews.com\/br\/#\/schema\/logo\/image\/","url":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/09\/4.jpg","contentUrl":"https:\/\/cryptonews.com\/wp-content\/uploads\/sites\/13\/2023\/09\/4.jpg","width":1669,"height":874,"caption":"Cryptonews Portugal"},"image":{"@id":"https:\/\/cryptonews.com\/br\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/posts\/142561","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/users\/311"}],"replies":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/comments?post=142561"}],"version-history":[{"count":4,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/posts\/142561\/revisions"}],"predecessor-version":[{"id":142605,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/posts\/142561\/revisions\/142605"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/media\/105638"}],"wp:attachment":[{"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/media?parent=142561"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/categories?post=142561"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/tags?post=142561"},{"taxonomy":"editores","embeddable":true,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/editores?post=142561"},{"taxonomy":"sponsored_companies","embeddable":true,"href":"https:\/\/cryptonews.com\/br\/wp-json\/wp\/v2\/sponsored_companies?post=142561"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}