Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

15 / 15 results
Active filter:tag: #github✕ clear
AI coding agents execute malicious Git config commands outside sandboxhighbug_reportVulnerability
bug_reportVulnerability

AI coding agents execute malicious Git config commands outside sandbox

Seven command-line AI coding agents: goose (fixed in 1.44.0), Codex CLI/Desktop (fixed in 0.131.0 / 26.519.x), Claude Code (partially fixed in 2.1.196, second path unpatched in 2.1.252+), Hermes Agent 0.18.2–0.21.0 (unpatched), Qwen Code 0.19.6–0.22.…

Anthropic2 Sep · 12:06 UTC
ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2highbug_reportVulnerability
bug_reportVulnerability

ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2

Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.

npm6 Aug · 20:26 UTC
GitHub Actions Abused to Scan and Exploit cPanel/WHM Servershighperson_alertThreat Actor
person_alertThreat Actor

GitHub Actions Abused to Scan and Exploit cPanel/WHM Servers

The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.

GitHub23 Jul · 09:28 UTC
FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes Malware via 7,600 Malicious GitHub Repos

FakeGit is a threat actor conducting a large-scale supply chain attack campaign targeting the software development community. The actor's motivation centers on mass malware distribution through the compromise of developer trust in the GitHub platform…

GitHub21 Jul · 20:34 UTC
FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Reposhighperson_alertThreat Actor
person_alertThreat Actor

FakeGit Campaign Distributes SmartLoader via 7,600+ Malicious GitHub Repos

FakeGit is a campaign (not a named threat actor group) targeting software developers through a large-scale supply chain attack leveraging GitHub's trusted platform.

GitHub20 Jul · 16:23 UTC
GitHub commit verification flaw allows signature reuse on rewritten commitshighbug_reportVulnerability
bug_reportVulnerability

GitHub commit verification flaw allows signature reuse on rewritten commits

GitHub's commit verification system for GPG/SSH-signed commits. All repositories using signed commits with GitHub's "Verified" badge are potentially affected. The flaw is in GitHub's verification logic, not Git itself.

GitHub8 Jul · 09:51 UTC
GitHub Agentic Workflows leak private repo data via public issueshighbug_reportVulnerability
bug_reportVulnerability

GitHub Agentic Workflows leak private repo data via public issues

GitHub Agentic Workflows with cross-repository read access. Organizations using GitHub agents that can access both public and private repositories are vulnerable. No CVE assigned yet.

GitHub7 Jul · 12:04 UTC
Fake GitHub PoC repos deliver ChocoPoC trojan to security researchershighbug_reportVulnerability
bug_reportVulnerability

Fake GitHub PoC repos deliver ChocoPoC trojan to security researchers

Vulnerability researchers and security professionals using GitHub to access proof-of-concept exploit code. The ChocoPoC malware targets Windows systems, stealing credentials, browser data, and files while establishing remote shell access.

GitHub2 Jul · 05:24 UTC
Miasma malware compromises npm packages LeoPlatform and RStreamshighbug_reportVulnerability
bug_reportVulnerability

Miasma malware compromises npm packages LeoPlatform and RStreams

npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.

npm26 Jun · 09:05 UTC
GitHub blocks pwn request attacks in actions/checkout starting June 2026highbug_reportVulnerability
bug_reportVulnerability

GitHub blocks pwn request attacks in actions/checkout starting June 2026

GitHub Actions workflows using actions/checkout with pull_request_target trigger. Organizations using GitHub Actions for CI/CD pipelines are affected. The security update applies to all repositories using the actions/checkout action after June 18, 20…

GitHub23 Jun · 12:22 UTC
npm v12 disables install scripts by default to block supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

npm v12 disables install scripts by default to block supply chain attacks

npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.

GitHub11 Jun · 04:23 UTC
Prompt injection in Claude Code GitHub Action exposes workflow secretshighbug_reportVulnerability
bug_reportVulnerability

Prompt injection in Claude Code GitHub Action exposes workflow secrets

Anthropic's Claude Code GitHub Action (prior to mitigation). Affects GitHub workflows using the action with access to repository secrets. Vulnerability exploitable when action processes untrusted input from pull requests or external sources.

Anthropic5 Jun · 14:46 UTC
CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repositorycriticalperson_alertThreat Actor
person_alertThreat Actor

CISA Contractor Leaks AWS GovCloud Keys on Public GitHub Repository

The threat actor is an insider—a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The individual intentionally published sensitive AWS GovCloud credentials and agency secrets to a public GitHub repository.

Amazon Web Services22 May · 14:34 UTC
Megalodon campaign injects 5,718 malicious commits into GitHub reposhighperson_alertThreat Actor
person_alertThreat Actor

Megalodon campaign injects 5,718 malicious commits into GitHub repos

Megalodon is an automated supply chain attack campaign targeting GitHub repositories. The actor's motivation appears to be exfiltration of CI/CD environment data, including secrets, tokens, and credentials stored in GitHub Actions workflows.

GitHub22 May · 09:55 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm20 May · 15:48 UTC