GitHub Security Crisis Escalates
Multiple security incidents including Grok Build exfiltration, GitLost, HalluSquatting, verified commit rewriting, Copilot jailbreak, 4000 private repo breach, and Microsoft removing 73 repos after malware. New AgentBaiting attacks target AI agents with 7,600 malicious repos. Miasma worm now uses genuine SLSA provenance from Red Hat, undermining trust in signed code. New npm supply chain attacks hit AsyncAPI and Jscrambler. Linux Foundation's Akrites initiative aims to protect open-source. GitHub has now announced new defenses: read-only mode, cache restrictions, Dependabot cooldown, and npm v12 changes to counter these attacks.
Sources (2)
Updated Jul 30, 2026