ended6월 6일· 1 sources

The Phantom Commit: How Attackers Exploited GitHub's Trust System

위조된 자동화 커밋, GitHub 신뢰 체계를 무너뜨리다

Why it matters

This incident exposes a critical flaw in GitHub's commit verification system: attackers forged automated commits that bypassed detection and infiltrated five repositories with credential-stealing malware targeting VS Code, Claude Code, and other popular development tools. Even security-conscious early adopters proved vulnerable, and GitHub's delayed response has left the malicious payload accessible and downloadable while the compromised account remains locked out.

1
Sources
+0
24h
Growth
4d
Active
Miasma wormGitHub breachsupply chaincredential stealerVS CodeClaude Code

Sources

Related Issues