Close Menu
    Facebook X (Twitter) Instagram
    Tuesday, July 1
    X (Twitter) Instagram LinkedIn YouTube
    Chain Tech Daily
    Banner
    • Altcoins
    • Bitcoin
    • Crypto
    • Coinbase
    • Litecoin
    • Ethereum
    • Blockchain
    • Lithosphere News Releases
    Chain Tech Daily
    You are at:Home » Hackers exploit SourceForge to hide crypto miners in Microsoft Office packages
    Crypto

    Hackers exploit SourceForge to hide crypto miners in Microsoft Office packages

    James WilsonBy James WilsonApril 9, 2025No Comments2 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cybercriminals are abusing SourceForge’s project domains to spread trojanized Office installers embedded with cryptocurrency mining tools and clipboard hijackers.

    A newly uncovered malware campaign is turning SourceForge’s infrastructure into a launchpad for infection, leveraging the platform’s developer-friendly tools to trick users into downloading malicious crypto software.

    According to researchers at Kaspersky, the scheme specifically targets crypto users by disguising malware as office-related downloads — complete with bloated installers, password-protected archives, and layers of obfuscation that eventually deliver a crypto miner and a ClipBanker to hijack crypto transactions.

    In a blog post on Tuesday, April 8, researchers said the attackers set up a fake project on SourceForge called “officepackage,” made to look like Microsoft Office add-ins copied from GitHub. While the project page itself might look normal, the real trap was its auto-generated subdomain “officepackage.sourceforge.io,” the researchers noted. Search engines like Russia‘s Yandex picked it up, and when users visited the page, they saw a fake list of office apps with download buttons that actually started the malware infection.

    Hackers exploit SourceForge to hide crypto miners in Microsoft Office packages - 1
    Example of a malicious Microsoft Publisher package shown on Yandex’s search results page | Source: Kaspersky

    Clicking the fake download links sends users through several redirects before delivering a small zip file. But once unzipped, it expands into a bloated 700MB installer.

    When launched, the installer uses hidden scripts to grab more files from GitHub, eventually unpacking malware that checks for antivirus tools before running. If no threats are detected, it installs tools like AutoIt and Netcat — one script sends system info to a Telegram bot, while another ensures the crypto-mining malware stays on the system, the researchers say.

    Kaspersky says 90% of affected users appear to be in Russia, with over 4,600 hits between January and March. While the campaign primarily seeks to steal crypto funds, researchers warn that infected machines may also be sold to other threat actors.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAave DAO approves AAVE buybacks as part of the broader Aavenomics overhaul
    Next Article 21Shares brings physically-backed Dogecoin ETP to SIX Swiss Exchange
    James Wilson

    Related Posts

    American Bitcoin raises $220M to buy Bitcoin and mining rigs

    July 1, 2025

    Lido DAO approves dual governance model proposal

    July 1, 2025

    Circle applies for a U.S. trust bank to manage USDC reserves

    July 1, 2025
    Leave A Reply Cancel Reply

    Don't Miss

    American Bitcoin raises $220M to buy Bitcoin and mining rigs

    Lido DAO approves dual governance model proposal

    Circle applies for a U.S. trust bank to manage USDC reserves

    ‘We’re Back, Baby’ – Analyst Flips Bullish on Solana (SOL), Hints at Altcoins Outperforming Bitcoin (BTC)

    About
    About

    ChainTechDaily.com is your daily destination for the latest news and developments in the cryptocurrency space. Stay updated with expert insights and analysis tailored for crypto enthusiasts and investors alike.

    X (Twitter) Instagram YouTube LinkedIn
    Popular Posts

    American Bitcoin raises $220M to buy Bitcoin and mining rigs

    July 1, 2025

    Lido DAO approves dual governance model proposal

    July 1, 2025

    Circle applies for a U.S. trust bank to manage USDC reserves

    July 1, 2025
    Lithosphere News Releases

    AGII Deploys AI Reasoning Systems for Smart Contract Intelligence

    June 30, 2025

    Imagen Network Taps Solana to Roll Out AI-Powered Social Features for Decentralized Growth

    June 30, 2025

    AGII Expands Workflow Diagnostics to Improve AI Decision Audits

    June 29, 2025
    Copyright © 2025

    Type above and press Enter to search. Press Esc to cancel.