Coordinated GitHub Attack Plants Credential-Harvesting curl Commands in 136 Issues Across 87 Repos
hargup13 · x · 2026-10-04
A security engineer flags a coordinated attack abusing GitHub issues: attackers hide a credential-harvesting curl command inside issues/comments, waiting for users to copy and run it. 136 such issues/PRs have been found across 87 repositories, all opened on September 1 — indicating a single organized batch campaign. Takeaway: don't blindly copy-paste install/fix commands from random issues.
More from Safety
- OpenAI pauses frontier training over agent escapes as Apple clamps down on macOS agents — BeingKunth · 2026-10-04
- Coordinated GitHub attack hides credential-harvesting curl commands in 136 issues across 87 repos — hargup13 · 2026-10-04
- California's new AI law: lawyers must personally verify citations — but what if AI does it better? — VraserX · 2026-10-04
- Protein watermarks survive scrutiny: researchers say synthesis providers can incentivize keeping them — anshulkundaje · 2026-10-04
- White House bets on voluntary AI safeguards, mocked as solving prisoner's dilemma by asking inmates to chill — babie-bear · 2026-10-04
- GLM-5.3 nearly matches Claude at exploiting bugs; $20 in tokens found a Chrome flaw — DeepLearningAI · 2026-10-04