Mcap -- BTC -- ETH -- SOL -- BNB -- XRP -- F&G -- View Market
Loading prices…

OkoBot Malware Targets Crypto Wallets via Fake GitHub Projects

Diagram showing OkoBot malware infection chain targeting cryptocurrency wallets through GitHub and LinkedIn

Kaspersky has identified a new malware framework called OkoBot that delivers 20 distinct malicious payloads through a single encrypted channel, targeting cryptocurrency investors who trust GitHub repositories and LinkedIn job offers. The cybersecurity company published its findings on Wednesday, documenting an infection chain that begins with social engineering and ends with complete access to victims’ wallet files, browser data, and stored credentials.

What makes OkoBot particularly dangerous is its architecture. Unlike earlier campaigns that relied on scattered command-and-control infrastructure, this framework tunnels all 20 payloads through a single SSH connection. That design choice lets attackers maintain persistent access to infected machines while making network-level detection significantly harder. Your firewall sees one encrypted connection to a remote server; it has no visibility into the 20 separate tools running through that tunnel.

Kaspersky traced OkoBot’s lineage to TookPS, a malware campaign first spotted in 2025 that spread through fake software download sites. The evolution from TookPS to OkoBot shows how quickly threat actors iterate on successful techniques. What started as simple Trojan downloaders has become a modular framework capable of injecting malicious browser extensions, capturing wallet application windows in real time, and exfiltrating credentials at scale.

The GitHub Infection Vector

The primary infection chain exploits a technique called ClickFix, which manipulates users into executing commands they believe are harmless. Attackers create repositories on GitHub that appear to contain legitimate cryptocurrency tools, development libraries, or trading utilities. When a developer clones the repository and follows the installation instructions, they unknowingly trigger the initial payload.

GitHub’s reputation as a trusted platform works against victims here. Developers routinely pull code from repositories, install dependencies, and run build scripts without scrutinizing every line. The attackers understand this workflow intimately. They structure their malicious repositories to mirror legitimate projects: proper README files, realistic commit histories, and installation instructions that blend seamlessly with standard development practices.

Once the backdoor lands on an infected device, OkoBot begins harvesting. The malware scans for wallet files associated with popular Bitcoin and Ethereum software wallets. It captures browser data that might contain saved passwords or autofill information for exchange accounts. It looks for private keys stored in common locations. And it installs browser extensions that can intercept transactions in real time, modifying destination addresses before the user confirms a transfer.

The window-capture capability is particularly insidious. OkoBot can identify when a user opens a wallet application and begin recording the screen. If you type a seed phrase or display a QR code, the malware captures it. If you copy a private key to your clipboard, even briefly, OkoBot grabs it. The attack surface extends far beyond the initial infection.

Fake Recruiters Target Web3 Developers

A parallel campaign, documented by blockchain security firm SlowMist, uses LinkedIn as its distribution channel. Attackers create professional-looking profiles posing as Web3 recruiters at legitimate companies. They reach out to blockchain developers with job opportunities that seem too good to pass up: competitive salaries, remote work, equity stakes in promising projects.

The social engineering here is sophisticated. These aren’t Nigerian prince emails. The fake recruiters engage in extended conversations, building rapport over days or weeks. They ask about the developer’s experience, discuss hypothetical projects, and eventually send what appears to be a technical screening exercise. The victim receives a GitHub repository containing a “minimum viable product” they’re asked to evaluate before the interview.

“This attack is not an isolated case,” SlowMist wrote in a Saturday report. The firm noted that recent incidents show attackers “increasingly leveraging scenarios such as recruitment, code reviews and project collaborations to trick developers into actively running malicious repositories.”

The genius of this approach, if we can call it that, is that it exploits trust at every layer. LinkedIn provides the initial credibility. The extended conversation builds personal rapport. The GitHub repository looks like a legitimate code review exercise. And the installation workflow matches exactly what developers do dozens of times per week. By the time the malware executes, the victim has no reason to suspect anything unusual.

Diagram showing OkoBot malware infection chain from GitHub repository through SSH tunnel to 20 malicious payloads targeting crypto wallets

The malware delivered through this channel operates as a remote access trojan (RAT). Unlike OkoBot’s wallet-specific focus, this RAT provides attackers with broad access: project keys, cloud credentials, wallet extension data, and ongoing visibility into the developer’s work. For developers who work on DeFi protocols or manage multisig wallets, the consequences extend far beyond personal losses. A compromised developer might unknowingly give attackers access to protocol treasury keys or deployment credentials.

Connecting the Dots: A Broader Campaign Pattern

These two campaigns, while distinct, share tactical DNA with other sophisticated attacks we’ve covered this year. In April, CertiK warned crypto executives about Lazarus Group’s “Mach-O Man” malware, which hijacked routine Zoom calls to deploy credential-stealing payloads. That campaign also relied on trust exploitation: executives expect video calls with potential partners, and the malware embedded itself in what appeared to be standard meeting software.

The common thread across all these attacks is social engineering at scale. Technical exploits against blockchain protocols grab headlines because the amounts stolen are often enormous. But the quieter, more persistent threat comes from attacks that target the humans who build and use these systems. A smart contract audit can catch a reentrancy vulnerability. No audit can catch a developer who willingly installs a malicious repository because they thought they were preparing for a job interview.

Kaspersky’s report came just one day after SlowMist issued a separate warning about macOS malware targeting Telegram sessions. That campaign aims to steal credentials and hijack accounts, ultimately redirecting victims to fake websites designed to harvest wallet recovery phrases. The attackers understand that crypto users often coordinate through Telegram, and compromising a trusted channel creates opportunities for subsequent attacks on entire communities.

Think about the second-order effects here. A developer at a DeFi protocol gets their Telegram hijacked. The attacker can then impersonate that developer in group chats, potentially convincing other team members to execute malicious commands or approve fraudulent transactions. The initial malware infection is just the beginning of an attack chain that can propagate through social networks.

Defense Requires Institutional Paranoia

What can developers and investors actually do about threats like OkoBot? The security recommendations sound basic because they are: verify the authenticity of repositories before installing dependencies, be skeptical of unsolicited recruitment outreach, use hardware wallets for significant holdings. But implementation is harder than it sounds.

Consider a developer who receives three or four legitimate recruiting messages on LinkedIn per week. They work in a high-demand field. Companies genuinely do send GitHub repositories for technical screening. The signal-to-noise ratio is terrible, and attackers exploit exactly that confusion. Telling developers to “be careful” doesn’t scale when their professional success depends on engaging with exactly the kind of outreach that attackers mimic.

Hardware wallets help, but they’re not a complete solution. A hardware wallet protects the private key itself, but it can’t protect against a browser extension that modifies the destination address before you sign a transaction. If OkoBot changes the address in your wallet’s interface, you might sign a transaction sending funds to the attacker while believing you’re paying a legitimate counterparty. Checking addresses character by character helps, but realistically, how many people do that for every transaction?

The more durable defense is architectural. Sensitive operations should require multiple independent confirmations. Developers with access to protocol keys shouldn’t be running arbitrary code on the same machines. Multisig requirements should assume that any single signer might be compromised. The individual security practices matter, but they fail under pressure. The system design needs to account for those failures.

Our derivatives dashboard tracks funding rates and open interest across major platforms, useful for understanding market positioning, but it can’t tell you whether the person you’re chatting with on LinkedIn is actually a recruiter. The human layer remains the weakest link, and increasingly sophisticated attackers are building entire frameworks to exploit it.

Organizations in the crypto space should be running regular security training that goes beyond password hygiene. Developers need to understand specifically how these attacks work, what the red flags look like, and what verification steps they should take before executing code from unfamiliar sources. Investors need to understand that wallet security extends beyond seed phrase storage.

The UK’s recent sentencing of two hackers tied to a $115 million crypto ransom scheme shows that law enforcement is taking these threats seriously. But prosecution happens after the fact. The attackers behind OkoBot haven’t been identified, and their malware is actively circulating. Kaspersky confirmed multiple successful attacks since January 2026.

For readers tracking the broader market, our market dashboard provides total crypto market cap and BTC dominance data, but the security landscape is just as important to monitor. A major protocol compromise or a wave of developer account takeovers can move markets as quickly as any macroeconomic announcement.

The OkoBot framework represents a maturation of crypto-targeting malware. It’s modular, it’s stealthy, and it’s specifically designed to exploit the workflows that cryptocurrency developers and investors follow daily. The SSH tunnel architecture suggests the attackers are thinking about long-term persistence, not just quick smash-and-grab operations. They want ongoing access to compromised machines, which implies plans for continued exploitation.

Kaspersky noted that the framework “opens the door to copycat attacks.” Once a successful technique becomes public knowledge, other threat actors adopt and modify it. The ClickFix technique has already spread across multiple campaigns. The fake recruiter playbook is being replicated. Whatever defensive measures the industry implements, the attackers will iterate.

That iteration cycle is relentless. TookPS appeared in 2025 as a relatively simple Trojan downloader. Within roughly a year, it evolved into OkoBot: a 20-payload framework with sophisticated tunneling, wallet-capture capabilities, and browser extension injection. The next iteration will likely add capabilities we haven’t anticipated. The race between attackers and defenders continues, and right now, the attackers have momentum.

Bottom line
OkoBot’s evolution from simple Trojan to modular malware framework shows how quickly crypto-targeting attacks are maturing. The most dangerous aspect isn’t any single payload but the exploitation of developer trust through legitimate platforms like GitHub and LinkedIn.

Sources

Share:
Twitter Facebook LinkedIn Reddit WhatsApp Telegram Email