ended6월 10일· 1 sources

Thousands of GitHub Repos Still Harbor Active Malware—Here's How to Check

당신의 GitHub 저장소도 감염되었나? 공급망 악성코드 점검 가이드

Why it matters

A pervasive supply-chain malware is silently infecting thousands of GitHub repositories through compromised credentials, remaining undetected because it disguises itself as legitimate commits. Most victims have no idea their repos are infected, as the malware only activates when developers use common tools like npm or AI-assisted editors, potentially spreading to entire dependency chains. Knowing how to identify and safely remediate the infection is critical to prevent further supply-chain compromise.

1
Sources
+0
24h
Growth
103d
Active
supply-chain attackGitHub repositoriescredential harvestingmalware cleanupnpm security

Sources

Related Issues