logo

GitHub Rolls Out Default Secret Scanning Push Protection for Public Repositories

ID: 2d16fea7-fd02-5da2-b71e-bd1f9863c983

STIX ID: report--2d16fea7-fd02-5da2-b71e-bd1f9863c983

Feed Name: The Hacker News

Threat Score
65/100

Date Published: 2024-03-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

GitHub has enabled secret scanning push protection by default for public repositories to help prevent accidental exposure of credentials and tokens; the announcement comes amid an active "repo confusion" campaign that floods the platform with trojanized/obfuscated repositories and bogus packages distributing a stealer (BlackCap Grabber) aimed at stealing passwords and cryptocurrency from developer devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.