Chinese malware is flooding GitHub pages – HiddenGh0st, Winos and kkRAT hit devs via SEO poisoning

Chinese users are being targeted by malware campaigns using spoofed download sites and SEO poisoning kkRAT…

Continue Reading

GitHub supply chain attack sees thousands of tokens and secrets stolen in GhostAction campaign

GhostAction attack stole 3,325 secrets from 327 GitHub accounts GitGuardian helped shut it down and alerted…

Continue Reading

GitHub CEO resigns – is this the latest sign of its Microsoft absorption?

Thomas Dohmke resigns as GitHub CEO, effective by the end of 2025 GitHub is getting closer…

Continue Reading

GitHub calls for major expansion in open source funding from the EU

GitHub wants the EU to create a Sovereign Tech Fund for OSS maintenance Microsoft hasn’t committed…

Continue Reading

Hackers are hiding powerful info-stealing malware in fake free VPNs downloaded from GitHub, don’t get tricked

GitHub repositories host malware disguised as tools that gamers, and privacy-seekers are likely to download The…

Continue Reading

This GitHub trick could let attackers steal secrets from major projects, and no one’s paying attention

Sysdig exposed how a trusted GitHub feature can silently hand control to attackers pull_request_target isn’t just…

Continue Reading