Hacker News new | past | comments | ask | show | jobs | submit login
If you work at GitHub security, you are bad at your job
13 points by joshdotsmith 65 days ago | hide | past | favorite
This is getting to be embarrassing. It’s been almost a week of trying to alert GitHub to multiple spoofed repositories serving malware. Everyone appears to be sleeping on the job. The malware is easily compared to known IoCs, so it’s even easily automatable.

Can someone at GitHub wake the hell up already and stop serving malware?

Here’s an obvious one: https://github.com/ojas1103/CircleProgressKit

And others: https://github.com/AkashiKensei/Zenix-Account-Creator

https://github.com/MinhDuong2571/DNSrce

https://github.com/xcwv667/eth-input-call-data-builder

https://github.com/ForgedRice/deepseek-api-client

https://github.com/Losnunes/SHOOTER

https://github.com/Alexbochechudo/encode-reactjs-intermediate-2024

https://github.com/Dawsandos/monster-energy-theme/releases

https://github.com/popopopopopopopopopopopopopopo/TuneText

https://github.com/Cynicave/Crunchyroll-Account-Checker




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: