Thousands of GitHub repositories deliver fake PoC exploits with malware

TL;DR

Researchers at the Leiden Institute of Advanced Computer Science found thousands of repositories on GitHub that offer fake proof-of-concept (PoC) exploits for various vulnerabilities, some of them including malware.According to the technical paper from the researchers at Leiden Institute of Advanced Computer Science, the possibility of getting infected with malware instead of obtaining a PoC could be as high as 10.3%, excluding proven fakes and prankware.The researchers analyzed a little over 47,300 repositories advertising an exploit for a vulnerability disclosed between 2017 and 2021 using the following three mechanisms:Of the 150,734 unique IPs extracted, 2,864 matched blocklist entries, 1,522 were detected as malicious in antivirus scans on Virus Total, and 1,069 of them were present in the AbuseIPDB database.However, the researchers shared with BleepingComputer at least 60 other examples that are still live and in the process of being taken down by GitHub.Software testers are advised to carefully scrutinize the PoCs they download and run as many checks as possible before executing them."

Like summarized versions? Support us on Patreon!