Flying Under the Radar: Abusing GitHub for Malicious InfrastructureRecorded Future·Aug 22, 00:00 UTC · Aug 22, 2025Threat actor157
GitHub Action tj-actions/changed-files was compromised in supply chain attackSecurity Affairs·Mar 18, 10:17 UTC · Mar 18, 2025VulnerabilityCVE-2025-30066147
Google Cloud Platform Data Destruction via Cloud BuildCisco Talos·Feb 6, 11:00 UTC · Feb 6, 2025Vulnerability142
GitHub Actions Vulnerable to Typosquatting, Exposing Developers to Hidden Malicious CodeThe Hacker News·Sep 9, 12:05 UTC · Sep 9, 2024Malware142
GitHub Vulnerability 'ArtiPACKED' Exposes Repositories to Potential TakeoverThe Hacker News·Aug 17, 06:28 UTC · Aug 17, 2024Vulnerability42
There is no real fix to the security issues recently found in GitHub and other similar softwareCisco Talos·Aug 1, 18:00 UTC · Aug 1, 2024RansomwareCVE-2018-082460
Hackers Can Abuse Legitimate GitHub Codespaces Feature to Deliver MalwareThe Hacker News·Jan 18, 05:17 UTC · Jan 18, 2023Malware142
By end of 2023, GitHub to force code contributors to use twoThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Malware142
GitHub Bug Exposed Repositories to HijackingInfosecurity Magazine·Oct 27, 10:00 UTC · Oct 27, 2022Vulnerability42
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackThe Hacker News·Jun 9, 05:50 UTC · Jun 9, 2026Vulnerability142
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack RepositoriesThe Hacker News·Jun 4, 15:24 UTC · Jun 4, 2026Vulnerability142
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI CredentialsThe Hacker News·Mar 25, 06:34 UTC · Mar 25, 2026Data breachCVE-2026-3363460
Massive GitHub malware operation spreads BoryptGrab stealerSecurity Affairs·Mar 8, 13:38 UTC · Mar 8, 2026Malware42
Self-replicating worm hits 180+ npm packages in (largely) automated supply chain attackHelp Net Security·Sep 16, 00:00 UTC · Sep 16, 2025Data breach57
GitVenom campaign targets gamers and crypto investors by posing as fake GitHub projectsSecurity Affairs·Feb 26, 06:27 UTC · Feb 26, 2025Threat actor157
Millions Face RepoJacking Risk on GitHub RepositoriesInfosecurity Magazine·Jun 26, 17:00 UTC · Jun 26, 2023Vulnerability42
Okta revealed that its private GitHub repositories were hackedSecurity Affairs·Dec 21, 19:32 UTC · Dec 21, 2022Ransomware57
Cloud-Based Cryptocurrency mining attacks abuse GitHub Actions and Azure VMSecurity Affairs·Jul 12, 07:26 UTC · Jul 12, 2022Vulnerability42
Ubuntu-Maker Canonical’s GitHub Account Gets HackedThe Hacker News·Jul 7, 15:58 UTC · Jul 7, 2019Malware42
The Winnti Gang continues its activity and leverages GitHub for C&C CommunicationsSecurity Affairs·May 7, 12:32 UTC · May 7, 2018Malware42
Brazilian LofyGang Resurfaces After Three Years With Minecraft LofyStealer CampaignThe Hacker News·Apr 29, 08:29 UTC · Apr 29, 2026Malware42
Checkmarx supply chain attack impacts Bitwarden npm distribution pathSecurity Affairs·Apr 25, 21:59 UTC · Apr 25, 2026Data breach57
Handling people's personal data is sensitive businessTroy Hunt·Nov 22, 10:50 UTC · Nov 22, 2016Data breach57
GitHub Updates actions/checkout to Block Common Pwn Request Attack PatternsThe Hacker News·Jun 23, 14:22 UTC · Jun 23, 2026Vulnerability42
Packagist Supply Chain Attack Infects 8 Packages Using GitHubThe Hacker News·May 24, 08:14 UTC · May 24, 2026Vulnerability42
Grafana GitHub Breach Exposes Source Code via TanStack npm AttackThe Hacker News·May 20, 05:13 UTC · May 20, 2026Ransomware157
Legitify: Open-source scanner for security misconfigurations on GitHub and GitLabHelp Net Security·Apr 15, 00:00 UTC · Apr 15, 2026Vulnerability142
Hackers Use GitHub Repositories to Host Amadey Malware and Data Stealers, Bypassing FiltersThe Hacker News·Jul 21, 06:30 UTC · Jul 21, 2025Malware42
CISA Warns of Active Exploitation in GitHub Action Supply Chain CompromiseThe Hacker News·Mar 19, 06:31 UTC · Mar 19, 2025Advisory in the wildCVE-2025-3006660
390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting PoC ExploitsThe Hacker News·Dec 17, 04:40 UTC · Dec 17, 2024Exploit / PoC57
Phishing Tool GoIssue Targets Developers on GitHubInfosecurity Magazine·Nov 12, 15:15 UTC · Nov 12, 2024Phishing & fraud142
North Korean hackers targeted tech companies through JumpCloud and GitHubHelp Net Security·Jul 25, 10:40 UTC · Jul 25, 2023Malware42
More than a million GitHub repositories potentially vulnerable to RepoJackingSecurity Affairs·Jun 23, 06:59 UTC · Jun 23, 2023Vulnerability42
Octopus Scanner Malware: open source supply chain attack via NetBeans projects on GitHubSecurity Affairs·May 29, 12:22 UTC · May 29, 2020Malware42
Vulnerability reports are arriving faster than GitHub can review themHelp Net Security·Jun 30, 00:00 UTC · Jun 30, 2026Vulnerability in the wild57
Hades PyPI Attack: 19 Packages Poisoned to AutoThe Hacker News·Jun 9, 10:34 UTC · Jun 9, 2026Malware42
Miasma Supply Chain Attack Compromises Red Hat npm Packages with CredentialThe Hacker News·Jun 2, 08:55 UTC · Jun 2, 2026Vulnerability42
Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential StealerThe Hacker News·May 25, 09:00 UTC · May 25, 2026Malware142
Malicious Commands in GitHub Codespaces Enable RCEInfosecurity Magazine·Feb 5, 14:30 UTC · Feb 5, 2026Vulnerability142
Ongoing malvertising campaign targets European IT workers with fake GitHub Desktop installersHelp Net Security·Sep 9, 00:00 UTC · Sep 9, 2025Threat actor57