Last Update: 08/01/2026 at 2:00 PM EST

Attackers Target GitHub Developer Workflows

Coverage from BleepingComputer, The Record, and others

Articles

12

Active Days

148

The Topic

Attackers Target GitHub Developer Workflows topic image

Attackers are abusing GitHub repositories, Discussions, VS Code workflows, JavaScript bundles, and vulnerable web applications to steal credentials or deliver malware. The activity combines social engineering, repository impersonation, supply-chain compromise, exploitation of exposed secrets, and automated attacks against internet-facing software. The common risk is that trusted developer infrastructure and application artifacts can provide access to source code, cloud environments, accounts, and downstream users.

First Article: 02/17/26

Latest Article: 07/14/26

Summary

  • A VS Code web zero-day can be used to install a malicious extension and extract broadly scoped GitHub OAuth tokens from github.dev users.
  • Hundreds of fake GitHub repositories and redirectors impersonated legitimate software projects to distribute infostealer malware.
  • Fake VS Code security alerts in GitHub Discussions used fabricated CVEs, maintainer impersonation, and external downloads to target developers.
  • Researchers linked Shai-Hulud worm activity to malicious packages, compromised developer accounts, and repositories storing stolen credentials.
  • A scan of five million JavaScript applications found more than 42,000 exposed tokens, including repository, email, webhook, and cloud-related credentials.
  • Automated exploitation of vulnerable Next.js applications harvested AWS credentials, database secrets, SSH keys, and API tokens from at least 766 hosts.

History

07/25/2026

The story now places greater emphasis on active credential theft and supply-chain compromise across more delivery vectors, while tightening some details around the campaigns and affected artifacts. The Next.js exploitation remains central, but the reporting now more clearly frames developer infrastructure, malicious packages, and application bundles as interconnected attack paths.

07/24/2026

The story has broadened from general GitHub-related secret theft and malware activity into a more specific set of attack paths against developer tooling, web applications, and build artifacts. The new version adds concrete campaign details, including a VS Code zero-day, fake GitHub repository impersonation, and large-scale token and secret harvesting.

Full History

Featured

Timeline: 148 Days

Feb 17Mar 17Apr 14May 12Jun 9Jul 7

Additional Articles

⭐⭐⭐⭐⭐

shattered.io06-18-2026
On May 20, 2026, GitHub confirmed that TeamPCP exploited a poisoned VS Code extension to exfiltrate about 3,800 internal repositories after May 19 detection.
KrebsOnSecurity07-13-2026
CISA issued a postmortem in 2026 after a contractor published AWS GovCloud credentials and plaintext passwords in a public GitHub repository for nearly six months.
Databreachtoday07-09-2026
Bitdefender survey findings, GitLost repository exposure research, and CISA patch directives accompanied millions of records exposure in 23andMe, Medtronic, and Cerner incidents.
404 Media / Joseph Cox06-08-2026
Microsoft shut down over 70 GitHub repositories in 2020s after malicious commits reportedly planted credential-harvesting files affecting AI coding tools and GitHub Actions.
Techtimes / Kyle Belmonte07-03-2026
GitHub launched Public Monitoring on July 1 to scan public GitHub repositories for secret leakage and attribute exposed credentials to enterprises using identity graph matching.

⭐⭐⭐

BleepingComputer / Ben02-17-2026
Intruder researchers identified over 42000 exposed tokens in 5 million applications during a 2024 scan of front-end JavaScript bundles.
BleepingComputer / Bill Toulas03-27-2026
Socket reports an automated GitHub campaign of fake VS Code vulnerability alerts sending tagged developers to external malicious extension downloads.
BleepingComputer / Bill Toulas04-04-2026
Cisco Talos says a React2Shell (CVE-2025-55182) exploitation campaign compromised at least 766 cloud-hosted Next.js systems to harvest and exfiltrate credentials using NEXUS Listener.

⭐️⭐️

BleepingComputer / Bill Toulas02-25-2026
Developers using Bitbucket hosted Next.js projects faced a coordinated data exfiltration and remote code execution campaign recently.