logo

Hackers Compromised 10,000+ GitHub Repositories to Inject Malicious Script

ID: e94794ca-57a0-57b8-8f5b-de00f38605f2

STIX ID: report--e94794ca-57a0-57b8-8f5b-de00f38605f2

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-06-22

Date Updated: 2026-06-22

Author: Abinaya

...
...

A researcher uncovered a large-scale GitHub malware campaign in which attackers cloned legitimate repositories (preserving commit history and contributor metadata) and periodically inserted README links to ZIP archives that contained Trojan malware. The operation used evasion techniques—including splitting payloads across files and repeatedly updating README commits—to reduce automated detection, and an analysis of GH Archive data identified approximately 10,000 affected repositories that had remained undetected for extended periods.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.