ended6월 6일· 1 sources
The Phantom Commit: How Attackers Exploited GitHub's Trust System
위조된 자동화 커밋, GitHub 신뢰 체계를 무너뜨리다
Why it matters
This incident exposes a critical flaw in GitHub's commit verification system: attackers forged automated commits that bypassed detection and infiltrated five repositories with credential-stealing malware targeting VS Code, Claude Code, and other popular development tools. Even security-conscious early adopters proved vulnerable, and GitHub's delayed response has left the malicious payload accessible and downloadable while the compromised account remains locked out.
1
Sources
+0
24h
—
Growth
4d
Active
Miasma wormGitHub breachsupply chaincredential stealerVS CodeClaude Code