GitHub
-
GitHub agentic workflow flaw could expose private repositories, researchers say
Researchers say a prompt injection flaw in GitHub Agentic Workflows could let attackers use a public issue to pull data from private repositories without stealing an account or exploiting software vulnerabilities.
-
Fake reputation campaign pushes crypto clipper through GitHub, YouTube and news sites
A campaign used fake reputation signals across GitHub, SourceForge, YouTube and news sites to promote a crypto clipboard hijacker, according to a technical analysis from Check Point Research. The malware replaced copied wallet addresses with attacker-controlled ones.
-
North Korean hackers shift phishing campaign to GitHub repositories, researchers say
North Korean linked hackers used recruitment-themed phishing emails and malicious GitHub repositories to target nearly 100 organizations, researchers said. The campaign aimed to steal developer credentials and cryptocurrency wallet data across Windows, macOS and Linux.
-
GitHub to disable npm install scripts by default in version 12
GitHub said npm version 12 will disable install scripts by default next month to curb supply chain abuse. The change will also restrict Git and remote dependencies unless users explicitly allow them.
-
Microsoft removes 73 GitHub repositories during malware investigation
Microsoft removed 73 GitHub repositories on June 5 while investigating potential malicious content, briefly disrupting developer pipelines tied to Azure Functions. Researchers linked the incident to a broader Miasma and Shai-Hulud supply-chain campaign.
-
New npm supply chain worms hit 50-plus packages, steal secrets
Two npm supply chain attacks spread a Rust information stealer and a worm across dozens of packages, targeting developer secrets, cloud credentials and AI tool configurations. Researchers said the malware used GitHub and npm features to keep propagating.
-
Malicious npm package used GitHub uploads to steal files from AI workspace
A malicious npm package was found stealing files from Claude’s workspace directory by using GitHub uploads during installation. Researchers said the package hid the theft behind fake sync and network logs.
-
CrowdStrike and partners disrupt GlassWorm malware command channels
CrowdStrike said it and partners disrupted all command and control channels used by GlassWorm, a developer-targeting malware campaign that poisoned more than 300 GitHub repositories and used four separate infrastructure layers.
-
GitHub investigates claim of internal repository theft after TeamPCP listing
GitHub said it is investigating unauthorized access to internal repositories after TeamPCP claimed it was selling source code and internal data. The company said it has no evidence of customer impact outside internal repositories.
-
CISA left GitHub repo with passwords and keys exposed for six months
CISA left a public GitHub repository exposed for six months, revealing passwords, keys and tokens in production infrastructure files. GitGuardian found the leak on May 14 and the agency removed the repo the next day.









