
A secret network of around 3,000 “ghost” accounts on GitHub has been discovered manipulating the code-hosting platform to promote malware and phishing links. Recent research conducted by cybersecurity firm Check Point exposed the activities of a cybercriminal the researchers have named “Stargazer Goblin.”
Since June 2023 or even earlier, Stargazer Goblin has been active on Microsoft-owned GitHub, the world’s largest open-source code repository. The site hosts millions of developers’ projects, and Stargazer Goblin has been using its community tools to boost malicious code repositories’ visibility and perceived legitimacy.