A fake GitHub repo, a signed transaction: Kaspersky flags new crypto-malware wave
Researchers at Kaspersky say a previously undocumented malware strain is targeting crypto investors through counterfeit GitHub repositories and patient social engineering, and the first wallets may already be drained.

A counterfeit GitHub repository, dressed up as a cryptocurrency trading bot and quietly wired into a Discord support channel, has been used to drain investor wallets through a previously undocumented malware strain, Kaspersky researchers said on 18 July 2026. The Moscow-headquartered security firm disclosed the campaign in a public alert, warning that the code was being passed off in developer forums and chat groups frequented by retail traders looking for an edge.
The disclosure lands at a sensitive moment for the digital-asset industry. Self-custody has been pushed hard into the mainstream narrative as the answer to exchange failure, and retail participation in on-chain markets has been climbing through 2026. That growth has also widened the attack surface: a culture that rewards open-source tooling, speed and trust between strangers is, by construction, fertile ground for patient social engineers. The new campaign, as Kaspersky describes it, exploits precisely that seam.
The lure, and the script
According to the firm's write-up, the operators build cloned GitHub repositories that mirror legitimate trading-bot or wallet-adjacent projects. The repositories carry realistic-looking commit histories, fabricated star counts, README files written in fluent English, and contributor accounts that appear to have been active for months. Inside the code, a small loader sits waiting. Once a user clones the repository and runs the accompanying script, the loader executes in the background and stages a second payload that targets browser-based wallet extensions and clipboard activity.
Kaspersky's analysts describe a two-stage social-engineering script that runs alongside the technical exploit. The first contact is usually a public post in a trading or development channel offering a "free arbitrage bot" or a "gas-optimisation tool" with a public GitHub link. The second is a private message, sometimes days later, from an account posing as the project's maintainer, offering help with installation. The handoff is engineered to feel like developer culture: a user with a technical question gets a patient, technically literate answer, and a user with a wallet question gets steered toward running the script "to verify the configuration". The trust is built before the payload is dropped.
Once executed, the malware profiles the host machine for installed wallet extensions, harvests seed phrases stored in plaintext configuration files, and watches clipboard activity for addresses that match common cryptocurrency formats. Outbound transactions are then rewritten to attacker-controlled addresses. The infection is quiet by design: the user sees a signed transaction on their screen, but the destination is not the one they typed.
Why this wave feels different
Cryptocurrency-focused malware is not new. Clipboard hijackers have circulated since at least the 2018 wave of Electrum-targeted attacks, and supply-chain compromises of legitimate developer tools have hit the industry repeatedly. What Kaspersky's analysts argue sets this campaign apart is the operational patience on display. The cloned repositories have not been thrown up overnight. Several of the accounts flagged by the firm have posted issues and pull requests on adjacent projects, contributed to documentation, and built small public reputations before any malicious code was distributed.
That depth of cover matters because it exploits a specifically crypto-shaped culture. Open-source repositories are treated as a kind of public good: code is presumed honest until proven otherwise, and the social signals a developer accumulates over time are taken at face value. The campaign also leans on the messaging surfaces that sit closest to that culture, Discord and Telegram, where the lines between community support and private solicitation are deliberately blurred. The result is an attack that is technically modest but socially expensive to defend against.
The structural pattern here is familiar from other corners of the digital-asset economy. The same properties that make on-chain finance attractive to its users, permissionless access, pseudonymity, irreversible settlement, direct peer-to-peer tooling, are the properties that make it attractive to operators who want to launder value, harvest credentials, or simply move faster than any centralised defender can. The industry has spent years trying to split those two audiences with tools like hardware wallets, multisig and air-gapped signing. The new campaign does not break those tools. It bypasses them by convincing the user to do the work.
Who is exposed
Kaspersky has not named a specific threat actor, and the firm is explicit that attribution remains preliminary. The infrastructure overlaps seen across the cloned repositories suggest a single operator or a small cluster working from a shared playbook, but the geographic signals are thin. The languages used in the README files, the timezones of the contributing accounts, and the choice of target wallets are all consistent with a campaign built for a global retail audience rather than any one jurisdiction.
The exposure map, however, is clearer. Retail traders running their own bots, developers contributing to or evaluating small open-source projects, and users who treat Discord and Telegram as primary support channels are the immediate target demographic. Custodial exchange users are not directly in scope for this particular strain; the malware is built to harvest local wallet data, not exchange credentials. That distinction matters for any institutional response: the people most at risk are also the people least likely to be inside a corporate security perimeter.
There is also a softer exposure that does not show up in wallet balances. As these campaigns accumulate, they corrode the social contract that the open-source parts of the crypto economy depend on. If a developer cannot safely ship a tool without being mistaken for an attacker, and a user cannot safely evaluate a tool without being mistaken for a victim, the cost of doing business in the open rises for everyone.
What the defenders can actually do
The defensive playbook here is older than the malware. Treat unsolicited GitHub links, particularly those pushed through DMs, with the same suspicion a bank customer is now expected to apply to an unexpected wire request. Verify the maintainer's history independently rather than inside the channel the link arrived in. Keep seed phrases offline, and never paste them into a configuration file that lives on a machine that also runs untrusted scripts. Use a hardware wallet for any signing, and read the destination address on the device, not on the host screen. None of this is novel; the new campaign is notable mainly because it tests whether the lessons of the past eight years have actually been internalised.
There is also a structural question that the industry has been slow to answer. Open-source code review is distributed, slow, and largely volunteer. Threat-intelligence feeds are commercial, fragmented, and arrive after the damage is done. The gap between those two systems is exactly the seam this kind of operation is built to exploit. Closing it will require either a much more muscular code-signing and reputation layer than the ecosystem currently has, or a much more cautious default from users about which scripts they are willing to run. Neither shift is coming soon.
The first wallets may already be drained, the cloned repositories may already be cleaned up, and the maintainer accounts may already have pivoted to a new persona. That is the cadence of this kind of campaign. The interesting question is not whether the operators behind it will be caught, but how many more users will, over the rest of 2026, learn to read a GitHub link the way an experienced bank customer reads an unexpected wire request: slowly, sceptically, and only after checking the channel it came through.
Desk note: this article treats the Kaspersky disclosure as the wire event and avoids speculation about attribution, motive or jurisdictional reach beyond what the firm's published alert supports. Cointelegraph's Telegram wire carried the headline on 18 July 2026; the underlying Securelist research note is the load-bearing source for the technical claims.
Wire provenance
This editorial synthesis draws on the following public wire/social posts:
- https://t.me/s/cointelegraph
- https://t.me/s/cointelegraph