Build1 distinct publisher3 min readPublished
A Raxis post catalogues three campaigns that made GitHub the delivery host rather than the hiding place, which is why the 1,300 repositories flagged as open to RepoJacking matter more than the million-device headline above them.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
None of these three chains involved an exploit; the work being billed for was dressing. GitVenom's operators wrote professional READMEs, possibly generated with AI, built realistic commit histories, and tagged repositories with topics that matched popular developer interests, across hundreds of repositories over several years [4]. With more than 100 million repositories on the platform [2], a few hundred convincing ones cost nothing in signal-to-noise. A commit history is among the cheapest artifacts in software to fabricate and the slowest to earn.
The Lumma Stealer operation ran on the same asset. Repository names resembled popular legitimate tools, and release notes mimicked authentic software announcements [10]. The precondition Tant names is behavioural rather than technical: developers are conditioned to treat GitHub-hosted releases as legitimate software distributions [11]. The executable then arrives over the same hostname, through the same feature, as the real thing.
The figure I would interrogate before repeating is 1,300. The post says researchers identified over 1,300 repositories vulnerable to RepoJacking, which it defines as hijacking an existing repository and injecting malicious code into projects developers already trust [3]. That describes the outcome, not the precondition. It does not say who scanned, when, what counted as vulnerable, or whether the exposed names have since been claimed defensively. Without those, you cannot diff the list against your own dependencies, which is the only reason the count would matter to you rather than to a slide.
The proceeds number dates itself. Roughly five Bitcoin, described in the post as worth approximately US$440,000 [7]. That implies about $88,000 a coin [8], in a piece published on January 21, 2026 [1]. The five coins are the finding, while the dollar figure is just a quote from one afternoon.
Then the transfer question. The post's opening credits recent investigations with campaigns affecting nearly one million devices [14]. That reads as the Storm-0409 total again rather than an additional population, so the two figures should not be added [15]. GitVenom's bait was Instagram automation, Telegram bots and game hacking utilities [5], which sits closer to a working developer than streaming-site advertising does, and still closer to a weekend side project than to anything pinned in a build.
What does transfer is the takedown economics. The Storm-0409 operators maintained multiple repositories precisely so that removal of any one would not stop delivery [13]. Reporting a URL therefore buys hours. In my context, with third-party tooling entering builds from paths nobody re-verifies, that pushes the check onto the artifact instead of the location: a signature, or a hash I recorded myself and compare on the way in. The path stood in for a publisher check I never actually did.
Ranked by verification strength, evidence, and original report placement.
In the GitVenom campaign, attackers created hundreds of repositories over several years, each crafted to appear legitimate, featuring professionally written README files (possibly generated using AI), realistic commit histories, and topics aligned with popular developer interests.
The malicious GitVenom repositories offered tools for Instagram automation, Telegram bots, and game hacking utilities, designed to attract specific developer communities.
Trend Micro uncovered attackers abusing GitHub's release mechanism to host and distribute Lumma Stealer alongside other malware variants including SectopRAT, Vidar and Cobeacon.
In the Lumma Stealer chain, attackers created repositories with names similar to popular legitimate tools, used GitHub's release feature to upload malware-laden executables, and wrote repository descriptions and release notes that mimicked authentic software announcements, so victims downloaded what appeared to be official software releases.
Microsoft's analysis of the Storm-0409 malvertising campaign, which abused GitHub repositories, found it infected close to one million devices worldwide.
Storm-0409 was a three-stage attack that targeted users of illegal streaming platforms: victims clicked malicious ads on compromised streaming sites, were redirected to legitimate-looking GitHub repositories, and received NetSupport remote monitoring tools disguised as video codecs or streaming utilities; the attackers maintained multiple repositories to create redundancy that made takedown efforts less effective.
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 27, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
WSL is a working bridge, and npm hygiene stops at the container wall1 distinct publisher
build
Your scanner finds it in seconds; the average fix now takes 252 days1 distinct publisher
security
A trailer date is a campaign schedule: fake GTA 6 sites are selling stolen session cookies1 distinct publisher
build
AI-written code fails the same four ways, and every gate you own reports green1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single relayed vendor recap, no primary citations
Every factual load in the cluster rests on one republished security-firm blog post that names no report titles, links or dates. Named attributions (Microsoft, Trend Micro) are unverifiable from the supplied material, and the load-bearing counts - 1,300 RepoJacking-exposed repositories, hundreds of GitVenom repositories, ~5 BTC/US$440,000 - are unattributed or undated. The mechanics are internally coherent and specific enough to be checkable, which keeps this above the floor, but there is no corroboration and no second publisher.
Three real campaigns cited, all relayed secondhand
The technique described is in active real-world use rather than theoretical: three distinct campaigns are named with concrete mechanics, two attributed to named vendors, one carrying a close-to-one-million-device infection count and another traced crypto proceeds. That is genuine evidence of attacker uptake of GitHub as a delivery host. It is held down because all three observations reach the cluster through a single secondary summary with no dates, no IOCs and no indication of whether the campaigns are still live.
Headline scale overstated; mechanics roughly fair
The underlying pattern is real and specific, but the framing inflates it. The intro presents 'nearly one million devices' and 'hundreds of malicious repositories' as an aggregate of recent investigations, when the device count is Storm-0409's own total and the repository count is GitVenom's - the two cannot be summed. Language such as 'staggering', 'unprecedented scale' and 'tip of the iceberg' amplifies a re-presented single-campaign figure, and the dollar valuation is undated in a post republished seven months later. The campaign-level tradecraft descriptions are proportionate; the top-line numbers are not.
Security-firm content marketing on a developer platform
The post is a security consultancy's own blog, bylined to a named author at that firm, republished under the firm's account on dev.to - a distribution pattern whose purpose is developer-audience reach. The threat framing escalates ('numbers are staggering', 'tip of the iceberg') while omitting mitigations, links and vendor-neutral qualifications, which aligns with awareness-building rather than reporting. Third-party research from Microsoft and Trend Micro is invoked as credibility without citation. No sponsorship, product pitch or paid placement is disclosed in the supplied text, so this is a structural rather than demonstrated conflict.
Low: one publisher, no corroboration
Confidence is limited by structure rather than internal inconsistency. There is exactly one source, one publisher and no primary documents; the strongest supported findings are provenance and the internal double-count, both derivable from the text itself. Campaign mechanics are plausible and detailed but uncorroborated, the quantitative claims are unattributed or undated, and the truncated body means part of the argument is not in evidence.