A hacker inserted backdoors into over 130 GitHub repositories, targeting gamers and aspiring hackers with cheat tools and exploit kits.
Security researchers found malicious code disguised as safe and frequently updated repositories, with nearly 60,000 fake commits to appear credible.
The backdoors used PreBuildEvent scripts that downloaded malware upon code compilation, including trojans, RATs, and password stealers.
Experts warn users to verify open-source code, avoid running unfamiliar scripts on primary machines, and use sandboxed environments when testing suspicious tools to combat the growing threats in the open-source ecosystem.