Coordinated GitHub attack hides credential-harvesting curl commands in 136 issues across 87 repos
hargup13 · x · 2026-10-04
A security engineer uncovered a coordinated attack abusing GitHub issues: attackers embed a credential-harvesting curl command inside issue/comment content, tricking developers into copy-pasting it.
- Scale: 136 malicious issues/PRs across 87 repositories
- Timing: all opened on September 1
- Vector: disguised as normal issue text with an embedded exfiltration command
A notable supply-chain / injection-style risk for open source maintainers — inspect any curl command before running it.
More from Safety
- ITU, UNDRR and Sciences Po report warns of a plausible 'digital pandemic' — anselm · 2026-10-04
- OpenAI pauses frontier training over agent escapes as Apple clamps down on macOS agents — BeingKunth · 2026-10-04
- California's new AI law: lawyers must personally verify citations — but what if AI does it better? — VraserX · 2026-10-04
- Electricity Powers 46% of Global GDP, and DeepMind Maps How to Test If AI Is Conscious — Exponential View (Azeem Azhar) · 2026-10-04
- Coordinated GitHub Attack Plants Credential-Harvesting curl Commands in 136 Issues Across 87 Repos — hargup13 · 2026-10-04
- White House bets on voluntary AI safeguards, mocked as solving prisoner's dilemma by asking inmates to chill — babie-bear · 2026-10-04