Case of a stolen Git Identity

It was a Friday evening and I was casually writing up something for this site.

I had just managed to connect the domains and stuff and thought of googling my name to see what all shows up.

As expected, the results contained some X posts and GitHub repositories. But, the thing is, at that particular time, my GitHub profile had been suspended for reasons not fully clear to me.

As I scrolled down, I noticed that my profile was mentioned in certain cybersecurity articles.

Turns out, it was used by a North Korean group as part of a spam where they injected malicious scripts onto the system, most of these scripts were something that VSCode or an extension from it could run automatically. (Named: “PolinRider” by OpenSource Malware)

Last year, I had received some emails and LinkedIn messages asking me about certain Web3 repositories. I had asked all of those people to proceed with caution and report these repositories as they are not mine.

The thing is, it is very easy to impersonate someone via a commit. All one has to do is change the commit username and email in the local git config.

That is why it is always a good idea to setup GPG keys, which thankfully I had setup.

Anyways, after this discovery, I got in touch with Eastside McCarty from OpenSource Malware (one the sites that mentioned my account) via X and I also managed to detect a malicious script on my personal infrequently used laptop.

It was a fun exercise to go through all the shell histories and system logs to identify if I had a contact with an infected repo and if something from within those repositories was executed or not.

I shall leave those findings for another post.

Comments

Leave a comment