I found 10k GitHub repositories distributing Trojan malware
- Security
- Open Source
- Developer Tools
- AI
The post lays out a large malware campaign on GitHub. Attackers clone or mimic real repositories, tweak names and README text for search ranking, then send users to external ZIP archives that contain Trojan malware. The repos are kept artificially fresh by deleting and re-pushing commits, which helps them float to the top in GitHub and web search results. Several people said they had seen their own projects copied this way, or had reported near-identical repos over the past year, which makes the 10,000-repo count feel less like a freak find and more like one visible slice of an industrialized operation.
Treat GitHub discovery as untrusted distribution, not as a safety signal. If your team installs tools from repos found through search, add isolation, provenance checks, and malware scanning before anything touches a developer workstation or secrets.
- orchidfiles.com
- Discuss on HN