• About Us
  • Careers
  • Contact
No Result
View All Result
Sunday, August 10, 2025
DeFi Planet
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverses
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverses
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer
No Result
View All Result
DeFi Planet
No Result
View All Result
Home News

SourceForge Compromised by Hackers, Used to Distribute Crypto Miners via Microsoft Office Packages

9 April 2025
in News
Reading Time: 3 mins read
103 6
source: qz.com

source: qz.com

SourceForge, a popular open-source software development platform, distributes malicious cryptocurrency mining tools disguised as Microsoft Office packages.

This campaign, uncovered by researchers at Kaspersky, targets users by creating fake project pages that mimic legitimate software downloads, ultimately leading to the installation of crypto miners and clipboard hijackers.

The attackers set up a fake project on SourceForge called “officepackage,” which appears to offer Microsoft Office add-ins. However, the project’s auto-generated subdomain, “officepackage.sourceforge.io,” is the actual trap. Search engines like Yandex indexed this page, making it visible to users searching for office software. Upon visiting the page, users are presented with a list of fake office apps, complete with download buttons that initiate the malware infection.

Once a user clicks on these fake download links, they are redirected multiple times before receiving a small zip file. Unzipping this file reveals a surprisingly large 700MB installer. When launched, the installer uses hidden scripts to fetch additional files from GitHub, eventually unpacking malware that checks for antivirus software. If no threats are detected, it installs tools like AutoIt and Netcat. One script sends system information to a Telegram bot, while another ensures the persistence of the crypto-mining malware on the system.

Kaspersky reports that approximately 90% of affected users are located in Russia, with over 4,600 hits recorded between January and March. The primary goal of this campaign is to steal cryptocurrency funds by exploiting infected machines for mining. However, researchers warn that these compromised systems may also be sold to other threat actors, potentially leading to further malicious activities.

This incident highlights the evolving tactics of cybercriminals in exploiting trusted platforms to spread malware. Users are advised to be cautious when downloading software from unfamiliar sources and to ensure their antivirus software is up-to-date. The use of SourceForge’s infrastructure in this campaign underscores the need for vigilance in the open-source community and the importance of verifying the authenticity of software downloads.

The exploitation of SourceForge to distribute crypto miners via fake Microsoft Office packages is a significant security concern. It emphasizes the importance of cybersecurity awareness and the need for robust protection measures against sophisticated malware attacks. As the threat landscape continues to evolve, staying informed about such tactics is crucial for protecting both personal and financial data.

 

If you want to read more news articles like this, visit DeFi Planet and follow us on Twitter, LinkedIn, Facebook, Instagram, and CoinMarketCap Community.

“Take control of your crypto portfolio with MARKETS PRO, DeFi Planet’s suite of analytics tools.”

Don't miss out!

Subscribe To Our Newsletter

Receive top education news, lesson ideas, teaching tips and more!
Invalid email address
Give it a try. You can unsubscribe at any time.
Thanks for subscribing!
Tags: CryptoMicrosoftSourceForge
Share63Tweet40Share11
Bobby Okposin

Bobby Okposin

Related Posts

Standard Chartered Backs Ethereum Treasury Companies Over Spot ETFs for ETH Exposure
Ethereum

Standard Chartered Backs Ethereum Treasury Companies Over Spot ETFs for ETH Exposure

7 August 2025
KakaoBank Sets Sights on South Korea’s Stablecoin Market Amid Regulatory Shift
Regulation

KakaoBank Sets Sights on South Korea’s Stablecoin Market Amid Regulatory Shift

7 August 2025
WLFI to Launch Loyalty Program for USD1 Stablecoin Holders with Selected Crypto Partners
Stablecoin

WLFI to Launch Loyalty Program for USD1 Stablecoin Holders with Selected Crypto Partners

7 August 2025
China Moves to Issue First Stablecoins via Hong Kong
Stablecoin

China Moves to Issue First Stablecoins via Hong Kong

7 August 2025

Editors Picks

Web3 in 2025: Where We Are, What’s Next, and What the Data Says

Web3 in 2025: Where We Are, What’s Next, and What the Data Says

byOlayinka Sodiq
21 July 2025
0

Which Pays Better Right Now: DeFi’s High-Yield Pairs or Traditional Finance’s Cash Vehicles?

Which Pays Better Right Now: DeFi’s High-Yield Pairs or Traditional Finance’s Cash Vehicles?

byOlayinka Sodiq
6 July 2025
0

The Future of Crypto Could Be Institutional—And That’s Not a Bad Thing

The Future of Crypto Could Be Institutional—And That’s Not a Bad Thing

byOlajumoke Oyaleke
30 June 2025
0

What Is a Rebase Token and How Does It Work?

What Is a Rebase Token and How Does It Work?

byOlajumoke Oyaleke
28 June 2025
0

Smart Contracts on Ethereum, Solana, vs. Other Blockchains

Smart Contracts on Ethereum, Solana, vs. Other Blockchains

byOlajumoke Oyaleke
26 June 2025
0

Read More

Chain of Thoughts

What Happens When AI Gets a Wallet?

What Happens When AI Gets a Wallet?

byOlu Omoyele
31 July 2025
0

...

The Game-changing Triumvirate: Blockchain, Data Science, and Artificial Intelligence

The Game-changing Triumvirate: Blockchain, Data Science, and Artificial Intelligence

byOlu Omoyele
30 June 2025
0

...

Are Stablecoins Bank Deposits?

Are Stablecoins Bank Deposits?

byOlu Omoyele
31 May 2025
0

...

DAOs and the Coordination of Human Endeavour

DAOs and The Coordination of Human Endeavour

byOlu Omoyele
27 April 2025
0

...

Markets Update

Your Weekend Crypto Roundup | August 2025 (Week 2)

2 days ago

US Ether ETFs Turn One: What $16.6B in Assets and Bullish Inflows Signal for the Future

7 days ago

Is ETH Restaking Driving Efficiency or Introducing a Dangerous Complexity?

1 week ago

Your Weekend Crypto Roundup | August 2025 (Week 1)

1 week ago

Meta’s $72 Billion AI Investment: A Strategic Shift from the Metaverse to Artificial Intelligence

1 week ago

Is Web3 Finally Solving Its Risk Problem? A Market Review of DeFi Insurance Models

2 weeks ago
Read More

Events

Rare Evo 2025
Rare Evo 2025
6 Aug 25
Las Vegas
CBDC Conference
CBDC Conference
9 Sep 25
Nassau

Spotlight

All about Ethereum
All about Algorand
All about Bitcoin
All about Gora

Press Releases

The New Bybit Web3 is Here–Fueling On-Chain Thrills with $200,000 Up for Grabs

bychainwire
8 August 2025
0

Moving Forward: Builders Are Proving What’s Possible with CARV’s AI Stack

bychainwire
8 August 2025
0

Caldera Announces Partnership with EigenCloud to Integrate EigenDA V2

bychainwire
7 August 2025
0

BYDFi Card Officially Launches: One Card to Seamlessly Bridge Web3 Assets and Real-World Spending

bychainwire
7 August 2025
0

Bybit’s Ben Zhou Charts Bold New Course to Rewrite Crypto Success at Mid-Year Keynote

bychainwire
6 August 2025
0

Read More

ADVERTISING

ABOUT

TEAM

CAREERS

CONTACT

TERMS & CONDITIONS

PRIVACY POLICY

© Copyright 2025 DeFi Planet

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Please enter and activate your license key for Cryptocurrency Widgets PRO plugin for unrestricted and full access of all premium features.

Add New Playlist

No Result
View All Result
  • News
    • People
    • Business
    • Crime
    • Regulation
    • Crypto
    • CBDC
  • Markets
    • Bitcoin
    • Ethereum
    • Stablecoins
    • Altcoins
    • Crypto ETFs
    • Memecoins
  • Policy
  • Articles
    • Press Releases
    • Opinion
    • Explainers
    • Guest Post
    • Sponsored
  • Directory
    • Companies
    • People
    • Products
    • Wallets
  • Multimedia
    • Videos
    • Podcasts
  • Learn
    • DeFi Basics
    • Tutorials
    • Reviews
    • Blockchain Fundamentals
  • Research
    • Case Studies
  • Explore
    • DeFi
    • Crypto Gaming
    • NFT
    • DAO
    • Metaverses
    • Glossary
  • Jobs
  • Markets Pro
    • DeFi Planet Pro
    • Spend Crypto
    • Swap Crypto
    • Coin Prices
    • Crypto Exchanges
    • Crypto Analyzer

© Copyright 2024 DeFi Planet   |   Terms & Conditions   |   Privacy Policy

-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00