Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Omnistealer malware campaign targets developers through GitHub

The malware utilizes public blockchains not just for payments, but also as part of its delivery system. Once activated, it extracts sensitive information from victims’ machines, exposing multiple forms of sensitive data simultaneously.

byEmre Çıtak
March 31, 2026
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

A global credential-stealing operation known as Omnistealer has emerged from a GitHub repository and freelance job offers targeting blockchain developers. Security researchers indicate that Omnistealer has the potential to rival major cyberattacks like WannaCry.

The malware utilizes public blockchains not just for payments, but also as part of its delivery system. Once activated, it extracts sensitive information from victims’ machines, exposing multiple forms of sensitive data simultaneously.

The malware’s triggering mechanism connects to the TRON or Aptos blockchains, which offer cost-effective operations. It reads hidden transaction data to access the Binance Smart Chain, which delivers additional malicious code. As noted by Nick Smart, chief intelligence officer at Crystal Intelligence, the “final payload” executed by Omnistealer can gather extensive information from compromised systems.

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

Omnistealer targets over 60 cryptocurrency wallet extensions, includes more than 10 password managers, and can affect browsers like Chrome and Firefox. Investigators have linked around 300,000 stolen credentials to this operation, which includes data from both cybersecurity firms and government agencies across the United States and Bangladesh.

The primary targets are developers and contractors, with attackers impersonating recruiters for well-known companies and freelance developers. As of January, researchers identified two common strategies. The first involves posing as recruiters who “hire” South Asian developers for test projects containing hidden malware. The second involves malicious developers submitting infected pull requests directly through GitHub.

South Asia, particularly India, has been targeted for its large pool of GitHub developers and economically vulnerable workforce. Some malicious activities are traced back to IP addresses in Vladivostok, Russia, previously linked to North Korean operations.

Some cryptocurrency wallets noted in this operation match those connected to a $1.5 billion theft by the Lazarus Group, raising concerns about ongoing financial exploitation. The social-engineering tactics resemble a North Korean subset known as Contagious Interview, according to Nick Carlsen from TRM Labs.

Carlsen emphasized that financial gain remains a primary objective for North Korean cyber operations. Stolen cryptocurrencies could be used to support military programs. The massive collection of credentials may also enable the creation of convincing fake profiles, facilitating fund laundering or selling access on underground markets.

Ransom-ISAC reported that Omnistealer’s structure complicates shutdown efforts, as attack components are embedded within blockchain transactions, making tracking difficult. The organization highlighted the technique of “hiding malicious payloads within blockchain” as an emerging strategy among threat actors.


Featured image credit

Tags: Githubomnistealer

Related Posts

Steam Next Fest sees one in five demos labeled for generative AI

Steam Next Fest sees one in five demos labeled for generative AI

June 17, 2026
Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

June 17, 2026
Roblox expands age-based account tiers worldwide with new parental controls

Roblox expands age-based account tiers worldwide with new parental controls

June 17, 2026
Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

June 17, 2026
Is Gemini down? Users report problems with Google Gemini

Is Gemini down? Users report problems with Google Gemini

June 17, 2026
Google releases Android 17

Google releases Android 17

June 17, 2026

LATEST NEWS

Steam Next Fest sees one in five demos labeled for generative AI

Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

Roblox expands age-based account tiers worldwide with new parental controls

Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

Is Gemini down? Users report problems with Google Gemini

Google releases Android 17

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Wiz Write

BoldVoice

Bith

Concisely

YourGPT

Sonoteller

RoomGPT

Rosie

LedgerUp

Call Annie

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.