GitHub

Fake AI Developer Tools Deliver Infostealers to Steal Credentials and Cloud API Keys

Cybercriminals are increasingly targeting AI developers by cloning trusted GitHub repositories and hiding malware inside fake developer tools. Netskope Threat Labs has linked the...

AsyncAPI npm Supply Chain Attack Deploys Miasma RAT via Compromised GitHub Actions

AsyncAPI’s npm ecosystem was hit by a supply chain attack that used compromised GitHub Actions workflows to distribute a Miasma-associated remote access trojan (RAT)....

Hackers Abuse SheetBest API to Exfiltrate Banking Credentials Into Google Sheets

GitHub is a trusted platform for millions of developers, but financially motivated threat actors are increasingly weaponizing its infrastructure. In a sophisticated new campaign,...

GitHub Actions Script Injection Flaws Hit 38% of Organizations

GitHub Actions has quickly become a primary battleground for software supply chain attacks. According to the newly released 2026 State of DevSecOps report, a...

Threat Actor’s GitHub Token Leaked by AI-Generated npm Malware

The open-source software supply chain is facing another bizarre and careless attack. Cybersecurity researchers at OX Security have discovered a malicious npm package designed...

Popular

Subscribe