Coordinated GitHub attack hides credential-harvesting curl commands in 136 issues across 87 repos

hargup13 · x · 2026-10-04

A security engineer uncovered a coordinated attack abusing GitHub issues: attackers embed a credential-harvesting curl command inside issue/comment content, tricking developers into copy-pasting it.

A notable supply-chain / injection-style risk for open source maintainers — inspect any curl command before running it.

Related event: Coordinated GitHub issues attack hides credential-stealing commands across 87 repos(2 posts)→

Original post →

More from Safety

Safety channel →