A reported attempt to hide malicious code in a real repository, paired with a fake account, shows how software trust can be strained long before any payload is confirmed to have landed.
Attackers are using AI-branded lures and cloned GitHub repositories to push infostealers toward developers and AI users, with credentials and cloud secrets in the crosshairs.
Cloned repositories, infostealers, and social-engineering lures are turning routine AI setup work into a path to cloud credential theft.
A campaign involving compromised GitHub repositories and tainted Packagist releases shows how software delivery systems can be turned against cPanel and WHM operators.
A sprawling repository-abuse campaign linked to FakeGit used roughly 7,600 GitHub repos and more than 14 million downloads to push SmartLoader and StealC, showing how platform trust can become malware transport.
A malware campaign used deceptive GitHub repositories and AI-facing registry surfaces to make a loader look like a useful project, showing how quickly trusted setup paths can be turned against developers and agents.
A staged abuse pattern built on public code hosting, Go, PowerShell, and dead-drop indirection shows how ordinary developer infrastructure can be repurposed for malware delivery.
A seemingly harmless GitHub project can become dangerous the moment an agentic coding tool is told to clone it, set it up, and trust what comes next.
A contained extortion incident is a reminder that source control, release workflows, and repository secrets can matter as much as production servers.
An unverified extortion claim tied to GitHub-branded internal material shows how leak pressure can matter even when no ransomware encryption is in sight.
A reported worm tied to 73 Microsoft repositories on GitHub shows how modern coding tools can turn a project open into a security event.
Dozens of Microsoft-linked repositories were disabled in a rapid enforcement wave, showing how trusted developer assets can be repurposed as malware distribution points.
Seventy-three repositories across four Microsoft GitHub organizations were affected, and access was disabled, but the deeper lesson is how quickly source-control trust can become an incident response problem.
A flaw in Claude Code’s GitHub Actions integration could have let hostile input reach privileged automation, turning a convenience feature into a repository security problem.
A large repository campaign shows how CI files can become the real target when attackers aim for credentials, tokens, and trust in the build pipeline.
A supply-chain compromise around Laravel-Lang shows how release metadata, not just source code, can become the point where trust breaks.
A reported six-hour burst of malicious workflow changes shows how fast repository automation can turn from developer utility into a credential-exfiltration path.
A supply-chain incident did not stop at the package registry; one unrotated GitHub credential appears to have kept a door open into source repositories.
A GitHub-linked repository breach tied to a poisoned Nx Console VS Code extension shows how developer tooling can become the soft underbelly of source-code security.
Grafana’s GitHub breach shows how supply-chain compromise can spill beyond packages and into source-control systems, turning code theft into extortion.