WeSearch

Malvertising Campaign Spoofs GitHub to Deliver macOS Trojans

Roshan· ·5 min read · 0 reactions · 0 comments · 14 views
#malware#cybersecurity#advertising#ai#github
Malvertising Campaign Spoofs GitHub to Deliver macOS Trojans
⚡ TL;DR · AI summary

A malvertising campaign has been identified that uses a spoofed GitHub page to distribute macOS Trojans. The campaign disguises itself as a legitimate project called 'Jarvis AI Assistant' to lure users into downloading a trojanized installer. By employing zero-width space characters, the attackers evade detection and deliver malware through a convincing facade.

Key facts
Original article
Hacker News (Newest) · Roshan
Read full at Hacker News (Newest) →
Opening excerpt (first ~120 words) tap to expand

Malvertising Campaign Spoofs GitHub to Deliver macOS TrojansEvasive technique combines zero-width space (ZWSP) with Github spoofing to deliver malware through malvertisingRoshan, Eliya Stein, and ConfiantJun 02, 20261ShareCross-posted by Roshan"This campaign exploits the current popularity of AI utilities by using GitHub-spoofed infrastructure to distribute a trojanized version of an open-source repository with over 500 stars."- ConfiantWe recently detected a malvertising campaign distributing malware: a trojanized macOS Electron installer. The ad campaign was disguised to look like a legitimate personal open-source project called “Jarvis AI Assistant,” a speech-to-text project with 500 stars on GitHub.

Excerpt limited to ~120 words for fair-use compliance. The full article is at Hacker News (Newest).

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments