Tag

#GitHub

30 stories taggedGitHub · page 2 of 2.

Illustration for the story: OpenMandriva Linux Says Angry Contributor Wiped Years of Work
Identity & Access

OpenMandriva Linux Says Angry Contributor Wiped Years of Work

A developer with admin keys deleted repositories and pushed a package that could have broken user systems, after a dispute over the project's direction.

3 min read
Illustration: a developer's dark wooden desk at night, a laptop screen glowing with abstract green code
Threat Intelligence

Poisoned Injective SDK on npm quietly stole crypto wallet keys for hours

A hijacked contributor account on GitHub pushed a booby-trapped version of a popular blockchain toolkit, siphoning seed phrases from any developer who ran the wrong function.

4 min read
Illustration: a dim server room aisle at night, rows of dark server racks with faint green and amber status lights
Threat Intelligence

Old, Silent GitHub Accounts Are Being Used to Quietly Map Companies

Datadog Security Labs says several overlapping scraping campaigns are cataloguing corporate GitHub organisations using dormant 'ghost' accounts and stolen tokens.

3 min read
Illustration: a darkened developer workstation with a large monitor showing abstract cascading package dependency graphs
Policy & Regulation

npm 12 Turns Off Auto-Run Install Scripts to Blunt Supply Chain Attacks

GitHub's package manager for JavaScript now ships with a safer default, and it retires a token type that let developers skip two-factor login.

3 min read
Illustration: a glowing server rack inside a dark data centre
Threat Intelligence

Criminals Are Using GitHub's Own Public Tools to Map Your Company Before They Strike

Researchers at Datadog tracked months of quiet, automated snooping across GitHub that blends perfectly into normal traffic, and most organisations never notice it happening.

3 min read
A close-up, sharply focused photograph of a glowing laptop screen in a darkened office, showing lines of green and white code reflecting faintly on a glass desk
AI Security

A Hidden Note in a Bug Report Tricked GitHub's AI Into Leaking Company Secrets

Researchers showed how a single crafted message in a public GitHub issue could fool an AI assistant into reading private code and posting it online for anyone to see.

3 min read
Illustration: a developer workstation at night, two nearly identical strings of hexadecimal characters glowing softly
Cloud Security

GitHub's Green 'Verified' Badge Can Lie: Signed Commits Cloned Without the Key

Researchers show anyone can produce a second signed commit that matches the author, date and files of a real one, keeping GitHub's Verified stamp while carrying a different hash than developers recorded.

4 min read
Illustration: a glowing computer screen displaying dense lines of code in a dark room
AI Security

Researchers Show How a Fake GitHub Comment Can Trick AI Tools Into Leaking Secret Code

A crafted public comment on GitHub can manipulate AI-powered automation into handing over data from private repositories, no password required.

3 min read
Illustration: a glowing laptop screen displaying dense lines of green and white code in a dark room
AI Security

A Hidden Command in a GitHub Issue Can Silently Steal a Company's Private Code

Researchers found a flaw in GitHub's AI automation tool that lets an outsider read an organisation's private repositories by hiding plain-English instructions inside a public bug report.

3 min read
Illustration: a darkened developer workstation at night
Threat Intelligence

ChocoPoC: The Fake Exploit Repos Turning Bug Hunters Into Victims

A Python-based infostealer is hiding inside GitHub proof-of-concept code marketed to vulnerability researchers, siphoning credentials, cookies, and files before dropping a remote shell.

3 min read
Illustration: a cluttered security researcher's desk at night: open laptop showing terminal-
Threat Intelligence

ChocoPoC RAT Hides in Fake GitHub Exploits, Targets Security Researchers

A cluster of trojanized proof-of-concept repositories is pushing a Python-based remote access trojan to the very people who go looking for them.

3 min read
Illustration: GitHub Actions workflow interface showing secure code execution, digital screen, repository checkout process
Vulnerabilities

GitHub Hardens actions/checkout Against Pwn Request Exploits

From 18 June 2026, the updated action blocks malicious code execution through pull_request_target workflows.

3 min read
Illustration: A digital lock symbol overlaying a blurred GitHub interface, symbolizing enhanced security measures
Vulnerabilities

GitHub Tightens Security to Counter Pwn Request Attacks

actions/checkout v7 automatically blocks workflows that pull unreviewed fork code inside pull_request_target events, with backports arriving July 16.

2 min read
Illustration: a developer workstation with a glowing monitor showing abstract blue code editor panels
Vulnerabilities

One-Click VS Code Flaw Exposed GitHub OAuth Tokens to Theft

A researcher-disclosed bug in Microsoft's browser-based VS Code variant let a single crafted link siphon tokens with read/write access to private repos.

3 min read
Illustration: a dark server room with cascading green code reflections on glass partitions
Threat Intelligence

Miasma Self-Replicating Worm Reaches Microsoft GitHub Orgs, 73 Repos Affected

The campaign tracked publicly as Miasma propagated into Azure, Azure-Samples, Microsoft, and MicrosoftDocs before GitHub pulled access.

3 min read
© 2026 Threat Vectr