Over 100 GitHub Repositories Distributing BoryptGrab Stealer
The malware targets browser and cryptocurrency wallet data, along with system information and user files. The post Over 100 GitHub Repositories Distributing BoryptGrab Stealer appeared first on SecurityWeek.
A new information stealer has been distributed through a network of more than 100 GitHub repositories, Trend Micro reports.
Dubbed BoryptGrab, the malware can harvest browser and cryptocurrency wallet data, along with system information and user files.
Additionally, certain iterations of the stealer can drop a backdoor dubbed TunnesshClient, which uses an SSH tunnel for command-and-control (C&C) communication.
Source: https://www.securityweek.com/over-100-github-repositories-distributing-boryptgrab-stealer/
Related breach coverage
- Massive GitHub malware operation spreads BoryptGrab stealer2026-03-08
Trend Micro found BoryptGrab stealer spreading through 100+ GitHub repositories, stealing browser data, crypto wallets, system information, and user files. Trend Micro uncovered a campaign distributing the BoryptGrab information stealer through more than 100 GitHub repositories. BoryptGrab is designed to collect browser and cryptocurrency wallet data, system details, and common files. Some variants also deploy […]
- ‘Arkanix Stealer’ Malware Disappears Shortly After Debut2026-02-24
Written in C++ and Python, the malware exfiltrates system information, browser data, and steals files. The post ‘Arkanix Stealer’ Malware Disappears Shortly After Debut appeared first on SecurityWeek.
- New Wiper Malware Targeted Venezuelan Energy Sector Prior to US Intervention 2026-04-22
Dubbed Lotus Wiper, the malware targets recovery mechanisms, overwrites drives, and systematically deletes files. The post New Wiper Malware Targeted Venezuelan Energy Sector Prior to US Intervention appeared first on SecurityWeek.
- Venom Stealer Raises Stakes With Continuous Credential Harvesting2026-03-31
Licensed malware with built-in persistence and automation enables attackers to continuously siphon credentials, session data, and cryptocurrency assets. The post Venom Stealer Raises Stakes With Continuous Credential Harvesting appeared first on SecurityWeek.
