GitHub¤ò°ÍѤ·¤Æ¥Þ¥ë¥¦¥§¥¢ÇÛÉÛ¡¢ÉÔ¿³¤ÊÄÌÃΥ᡼¥ë¤ËÃí°Õ
Bleeping Computer¤Ï9·î19Æü(Êƹñ»þ´Ö)¡¢¡ÖClever 'GitHub Scanner' campaign abusing repos to push malware¡×¤Ë¤ª¤¤¤Æ¡¢¹¶·â¼Ô¤¬GitHub¤ÎIssues¤ò°ÍѤ·¤Æ¥Þ¥ë¥¦¥§¥¢¤òÇÛÉÛ¤·¤¿¤È¤·¤Æ¡¢Ãí°Õ¤ò´µ¯¤·¤¿¡£Èï³²¼Ô¤ÏGitHub¤«¤éÀµµ¬¤ÎÄÌÃΥ᡼¥ë¤ò¼õ¿®¤¹¤ë¤¬¡¢ËÜʸ¤Ë¤Ï°°Õ¤Î¤¢¤ëWeb¥µ¥¤¥È¤Ø¤Î¥ê¥ó¥¯¤¬µºÜ¤µ¤ì¤Æ¤¤¤ë¤È¤¤¤¦¡£
Clever 'GitHub Scanner' campaign abusing repos to push malware
¡û¹¶·â¼ê½ç
GitHub¤ÎIssues¤Ï¡¢¥ê¥Ý¥¸¥È¥ê¤Îºî¶È¡¢µÄÏÀ¤Ê¤É¤òÄÉÀפǤ¤ë¥³¥ß¥å¥Ë¥±¡¼¥·¥ç¥ó¥Ä¡¼¥ë(»²¹Í¡§¡ÖAbout issues - GitHub Docs¡×)¡£GitHub¥æ¡¼¥¶¡¼¤ÏIssues¤ò»ÈÍѤ·¤Æ¥Õ¥£¡¼¥É¥Ð¥Ã¥¯¤òÁ÷¼õ¿®¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£
º£²ó¡¢¹¶·â¼Ô¤Ï¤³¤Îµ¡Ç½¤ò°ÍѤ¹¤ë¤¿¤á¡¢µ¶¤ÎGitHub¥¢¥«¥¦¥ó¥È¤òºîÀ®¡£µ¶¥¢¥«¥¦¥ó¥È¤«¤éɸŪ¥×¥í¥¸¥§¥¯¥È¤Ëµ¶Issue¤òÊó¹ð¤¹¤ë¤³¤È¤Ç¡¢GitHub¤«¤é°°Õ¤Î¤¢¤ë¥á¡¼¥ë¤òÁ÷¿®¤µ¤»¤Æ¤¤¤ë¡£¥á¡¼¥ë¤ÏGitHub¸ø¼°¤«¤éÁ÷¿®¤µ¤ì¤ë¤¿¤á¡¢¥á¡¼¥ë¥Õ¥£¥ë¥¿¡¼¤Ê¤É¤ò²óÈò¤·¤ÆÈï³²¼Ô¤ËÁ÷¿®¤µ¤ì¤ë¡£
¶¼°Ò¥¢¥¯¥¿¡¼¤¬ºîÀ®¤·¤¿µ¶Issue¤ÎÎã¡¡°úÍÑ¡§Bleeping Computer
µ¶¤ÎIssue¤Ë¤Ï°°Õ¤Î¤¢¤ëWeb¥µ¥¤¥È¡Ögithub-scanner[.]com¡×¤Ø¤Î¥ê¥ó¥¯¤¬Â¸ºß¤·¡¢¸ÀÍÕ¹ª¤ß¤ËÈï³²¼Ô¤òͶƳ¤¹¤ë¡£°°Õ¤Î¤¢¤ëWeb¥µ¥¤¥È¤ÏCAPTCHA¤Ë¤è¤ë¿Í´Ö³Îǧ¤ò¹Ô¤¤¡¢¥»¥¥å¥ê¥Æ¥£´ë¶È¤Ë¤è¤ë¼«Æ°¸¡½Ð¤ò²óÈò¤¹¤ë¡£Èï³²¼Ô¤¬CAPTCHA¤ò²óÈò¤¹¤ë¤È¡¢¡ÖVerification Steps(¸¡¾Ú¼ê½ç)¡×¤ÈÂꤹ¤ë¥³¥Þ¥ó¥É¤Î¼Â¹Ô¼ê½ç¤¬É½¼¨¤µ¤ì¤ë¡£
¥³¥Þ¥ó¥É¤Î¼Â¹Ô¤ò»Ø¼¨¤¹¤ëɽ¼¨ ¡¡°úÍÑ¡§Bleeping Computer
¤³¤Î¤È¤¥¯¥ê¥Ã¥×¥Ü¡¼¥É¤Ë¤Ï°°Õ¤Î¤¢¤ë¥³¥Þ¥ó¥É¤¬¥³¥Ô¡¼¤µ¤ì¤Æ¤ª¤ê¡¢Èï³²¼Ô¤¬»Ø¼¨Ä̤ê¤ËÁàºî¤¹¤ë¤È¾ðÊóÀà¼è¥Þ¥ë¥¦¥§¥¢¡ÖLumma Stealer¡×¤Ë´¶À÷¤¹¤ë¡£Lumma Stealer¤ÏWeb¥Ö¥é¥¦¥¶¤Îǧ¾Ú¾ðÊó¡¢Cookie¡¢±ÜÍ÷ÍúÎò¡¢¥¦¥©¥ì¥Ã¥È¡¢¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¾ðÊó¤Ê¤É¤µ¤Þ¤¶¤Þ¤Ê¾ðÊó¤òÀà¼è¤¹¤ëµ¡Ç½¤¬¤¢¤ê¡¢±Ê³À¤âÈ÷¤¨¤ë¤È¤µ¤ì¤ë¡£
¡û±Æ¶Á¤ÈÂкö
Bleeping Computer¤Ï¡¢¹¶·â¼Ô¤¬³«È¯¼Ô¤Îǧ¾Ú¾ðÊó¤òÀà¼è¤·¡¢¥µ¥×¥é¥¤¥Á¥§¡¼¥ó¹¶·â¤ò¼Â¹Ô¤¹¤ë¶²¤ì¤¬¤¢¤ë¤È¤·¤ÆÃí°Õ¤ò¸Æ¤Ó¤«¤±¤Æ¤¤¤ë¡£GitHub¤òÍøÍѤ¹¤ë¤¹¤Ù¤Æ¤Î³«È¯¼Ô¤Ë¡¢¤³¤Î¤è¤¦¤Ê¹¶·â¼êË¡¤¬Â¸ºß¤¹¤ë¤³¤È¤òǧ¼±¤·¤Æ·Ù²ü¤ò´Ë¤á¤Ê¤¤¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£
¡û¹¶·â¼ê½ç
GitHub¤ÎIssues¤Ï¡¢¥ê¥Ý¥¸¥È¥ê¤Îºî¶È¡¢µÄÏÀ¤Ê¤É¤òÄÉÀפǤ¤ë¥³¥ß¥å¥Ë¥±¡¼¥·¥ç¥ó¥Ä¡¼¥ë(»²¹Í¡§¡ÖAbout issues - GitHub Docs¡×)¡£GitHub¥æ¡¼¥¶¡¼¤ÏIssues¤ò»ÈÍѤ·¤Æ¥Õ¥£¡¼¥É¥Ð¥Ã¥¯¤òÁ÷¼õ¿®¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£
º£²ó¡¢¹¶·â¼Ô¤Ï¤³¤Îµ¡Ç½¤ò°ÍѤ¹¤ë¤¿¤á¡¢µ¶¤ÎGitHub¥¢¥«¥¦¥ó¥È¤òºîÀ®¡£µ¶¥¢¥«¥¦¥ó¥È¤«¤éɸŪ¥×¥í¥¸¥§¥¯¥È¤Ëµ¶Issue¤òÊó¹ð¤¹¤ë¤³¤È¤Ç¡¢GitHub¤«¤é°°Õ¤Î¤¢¤ë¥á¡¼¥ë¤òÁ÷¿®¤µ¤»¤Æ¤¤¤ë¡£¥á¡¼¥ë¤ÏGitHub¸ø¼°¤«¤éÁ÷¿®¤µ¤ì¤ë¤¿¤á¡¢¥á¡¼¥ë¥Õ¥£¥ë¥¿¡¼¤Ê¤É¤ò²óÈò¤·¤ÆÈï³²¼Ô¤ËÁ÷¿®¤µ¤ì¤ë¡£
¶¼°Ò¥¢¥¯¥¿¡¼¤¬ºîÀ®¤·¤¿µ¶Issue¤ÎÎã¡¡°úÍÑ¡§Bleeping Computer
µ¶¤ÎIssue¤Ë¤Ï°°Õ¤Î¤¢¤ëWeb¥µ¥¤¥È¡Ögithub-scanner[.]com¡×¤Ø¤Î¥ê¥ó¥¯¤¬Â¸ºß¤·¡¢¸ÀÍÕ¹ª¤ß¤ËÈï³²¼Ô¤òͶƳ¤¹¤ë¡£°°Õ¤Î¤¢¤ëWeb¥µ¥¤¥È¤ÏCAPTCHA¤Ë¤è¤ë¿Í´Ö³Îǧ¤ò¹Ô¤¤¡¢¥»¥¥å¥ê¥Æ¥£´ë¶È¤Ë¤è¤ë¼«Æ°¸¡½Ð¤ò²óÈò¤¹¤ë¡£Èï³²¼Ô¤¬CAPTCHA¤ò²óÈò¤¹¤ë¤È¡¢¡ÖVerification Steps(¸¡¾Ú¼ê½ç)¡×¤ÈÂꤹ¤ë¥³¥Þ¥ó¥É¤Î¼Â¹Ô¼ê½ç¤¬É½¼¨¤µ¤ì¤ë¡£
¥³¥Þ¥ó¥É¤Î¼Â¹Ô¤ò»Ø¼¨¤¹¤ëɽ¼¨ ¡¡°úÍÑ¡§Bleeping Computer
¤³¤Î¤È¤¥¯¥ê¥Ã¥×¥Ü¡¼¥É¤Ë¤Ï°°Õ¤Î¤¢¤ë¥³¥Þ¥ó¥É¤¬¥³¥Ô¡¼¤µ¤ì¤Æ¤ª¤ê¡¢Èï³²¼Ô¤¬»Ø¼¨Ä̤ê¤ËÁàºî¤¹¤ë¤È¾ðÊóÀà¼è¥Þ¥ë¥¦¥§¥¢¡ÖLumma Stealer¡×¤Ë´¶À÷¤¹¤ë¡£Lumma Stealer¤ÏWeb¥Ö¥é¥¦¥¶¤Îǧ¾Ú¾ðÊó¡¢Cookie¡¢±ÜÍ÷ÍúÎò¡¢¥¦¥©¥ì¥Ã¥È¡¢¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¾ðÊó¤Ê¤É¤µ¤Þ¤¶¤Þ¤Ê¾ðÊó¤òÀà¼è¤¹¤ëµ¡Ç½¤¬¤¢¤ê¡¢±Ê³À¤âÈ÷¤¨¤ë¤È¤µ¤ì¤ë¡£
¡û±Æ¶Á¤ÈÂкö
Bleeping Computer¤Ï¡¢¹¶·â¼Ô¤¬³«È¯¼Ô¤Îǧ¾Ú¾ðÊó¤òÀà¼è¤·¡¢¥µ¥×¥é¥¤¥Á¥§¡¼¥ó¹¶·â¤ò¼Â¹Ô¤¹¤ë¶²¤ì¤¬¤¢¤ë¤È¤·¤ÆÃí°Õ¤ò¸Æ¤Ó¤«¤±¤Æ¤¤¤ë¡£GitHub¤òÍøÍѤ¹¤ë¤¹¤Ù¤Æ¤Î³«È¯¼Ô¤Ë¡¢¤³¤Î¤è¤¦¤Ê¹¶·â¼êË¡¤¬Â¸ºß¤¹¤ë¤³¤È¤òǧ¼±¤·¤Æ·Ù²ü¤ò´Ë¤á¤Ê¤¤¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£