logo

GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say

ID: fcfe7404-c67b-559a-b1ac-d08465070a6a

STIX ID: report--fcfe7404-c67b-559a-b1ac-d08465070a6a

Feed Name: DataBreaches.Net

Threat Score
85/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Dissent

...
...

Researchers warn that variants of the Shai-Hulud supply-chain worm—originating with the TeamPCP cybercrime group—are infecting hundreds of software packages and developer accounts; formal vulnerability reports submitted to GitHub were rejected as ineligible, and copycat variants have been linked to breaches at the European Commission, Mercor, the LiteLLM package, GitHub, and Red Hat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.