True, some members fall victim to download malicious file because they think that if a project is hosted on GitHub, it's safe.
Things to be suspicious of are:
1.
The profile Age and activityy;
Very many times, the GitHub profile age is a few days or months old with less activity
Here is a scam I uncovered a few days ago with an attempt to spread malware
OWL Coin - Malware in the wallet [DO NOT DOWNLOAD]!!!If you look at the profile of the so called
project developerHe just joined 6 days ago with just only 3 contributions in the last year and the contributions are highlighted by one dot in April and boom wallet is ready
The three contributions were
- Joined GitHub
- Created their first repository April 27th
- Created 1 commit in 1 repository (projectsowa/coinowl 1 commit)
That was all
2.
Wallet link in the ANN is usually set up so that it can auto downloadsThis is done so that the user can not see how the GitHub activity looks like and become suspicious
This is the way the scam set up his, as soon as you click on the link, it auto downloads
https://github.com/projectsowa/coinowl/raw/master/Owlcoin-win64-qt.zip
3.
Files however small they are usually are zippedThis is done so that online virus detectors like virustotal
may not be able to detect the malware at times
Some checks users can do- Look at the account age
- Is the activity high in the repository? Are the developers verified and credible?
- Virustotal might not be 100% accurate but it's sometimes a savior, scan all downloaded files
- always have a strong AV on your computer if you are found of downloading this hosted files
- Verify signatures of file releases before installation
- Simply avoid suspicious and unpopular ICO/Master node project wallet downloads