Kaspersky has identified a malware operation called GitVenom that targeted cryptocurrency investors and developers through fake GitHub projects. The campaign reportedly relied on more than 200 fraudulent repositories made to look like legitimate software, code samples, or crypto-related tools.
According to the findings, the attackers boosted credibility with AI-generated documentation that helped the projects appear polished and trustworthy. Once victims downloaded and ran the offered files, they were exposed to trojanized applications designed to steal Bitcoin as well as sensitive information, including credentials.
The case highlights how public code-sharing platforms can be abused to spread malware when users trust repositories too quickly. Developers reviewing unfamiliar projects and crypto users searching for wallets, bots, or other tools may be especially vulnerable if they rely on surface-level signs such as detailed readme files or professional-looking project pages.
Kaspersky’s report points to a broader cybersecurity risk at the intersection of open-source ecosystems and digital assets. When malicious code is packaged as a useful GitHub project, the damage can extend beyond device compromise to direct financial loss and account takeover.