Tag: GitHub

Packagist Postinstall Malware: What Developers Should Check

A Packagist and GitHub supply-chain campaign used malicious postinstall hooks to fetch…

Stephanie Adlam

GitHub Internal Repos Exposed Through Poisoned VS Code Extension

GitHub says an employee device was compromised through a poisoned VS Code…

Stephanie Adlam

Shai-Hulud AntV npm Supply-Chain Wave: What Developers Should Check

Shai-Hulud returned in an AntV npm supply-chain wave affecting hundreds of packages.…

Stephanie Adlam

Mini Shai-Hulud Hits TanStack npm Packages With Signed Malware

Mini Shai-Hulud abused trusted publishing to ship malicious TanStack npm packages with…

Stephanie Adlam

Checkmarx Jenkins Plugin Compromise Put CI Secrets at Risk

A rogue Checkmarx AST Scanner Jenkins plugin release put CI/CD source code…

Stephanie Adlam

Operation HookedWing Phishing Hit 500+ Organizations

Operation HookedWing used GitHub Pages, compromised servers, and staged redirects to target…

Stephanie Adlam

SmartLoader, LummaStealer Abuse Fake GitHub Repositories

A new campaign has been discovered where malicious actors are leveraging AI…

Stephanie Adlam

GitHub Enterprise Server Auth Bypass Flaw Discovered

On May 21, 2024 GitHub disclosed a new authentication bypass flaw in…

Stephanie Adlam

GitHub and GitLab CDNs Abused to Spread Malware

Recent research around new spreading approaches of one stealer malware family revealed…

Stephanie Adlam

STRRAT and Vcurms Malware Abuse GitHub for Spreading

A new phishing campaign has recently been discovered that uses GitHub to…

Stephanie Adlam

RepoJacking Attacks Could Threaten Millions of GitHub Repositories

Aqua researchers believe that millions of repositories on GitHub are vulnerable to…

Malware in GitHub Repositories Is Spread From Fake Security Company Name

Researchers detected fake company accounts on GitHub linked to a deceitful cybersecurity…

Stephanie Adlam

AI Assistant

Hello! 👋 How can I help you today?