Last Update: 08/01/2026 at 2:00 PM EST

Attackers Target GitHub Developer Workflows

Coverage from BleepingComputer, The Record, and others

Articles

12

Active Days

148

The Topic

Attackers Target GitHub Developer Workflows topic image

Attackers are abusing GitHub repositories, Discussions, VS Code workflows, JavaScript bundles, and vulnerable web applications to steal credentials or deliver malware. The activity combines social engineering, repository impersonation, supply-chain compromise, exploitation of exposed secrets, and automated attacks against internet-facing software. The common risk is that trusted developer infrastructure and application artifacts can provide access to source code, cloud environments, accounts, and downstream users.

First Article: 02/17/26

Latest Article: 07/14/26

History

07/25/20260 new articles

The story now places greater emphasis on active credential theft and supply-chain compromise across more delivery vectors, while tightening some details around the campaigns and affected artifacts. The Next.js exploitation remains central, but the reporting now more clearly frames developer infrastructure, malicious packages, and application bundles as interconnected attack paths.

07/24/20260 new articles

The story has broadened from general GitHub-related secret theft and malware activity into a more specific set of attack paths against developer tooling, web applications, and build artifacts. The new version adds concrete campaign details, including a VS Code zero-day, fake GitHub repository impersonation, and large-scale token and secret harvesting.

  • VS Code zero-day in github.dev can expose broadly scoped GitHub OAuth tokens.
  • Hundreds of fake GitHub repositories impersonated legitimate software.
  • More than 42,000 tokens were found in JavaScript bundles.
  • Automated Next.js exploitation harvested secrets from at least 766 hosts.
  • Fake security alerts used GitHub Discussions and fabricated CVEs.
07/24/20264 new articles

The story has widened from repeated developer-supply-chain credential theft into a more explicit GitHub-centered security campaign that now includes public monitoring, takedowns, and broader incident handling issues. The current version also adds new actors and a stronger emphasis on disclosure failures and operational response.

  • GitHub is expanding public monitoring and secret-scanning controls.
  • CISA appears as a newly exposed government victim and later commentator.
  • GitHub.dev and repository Discussions are now cited as attack paths.
  • Disclosure handling problems include delayed remediation and rejected reports.
  • GitHub Agentic Workflows are newly mentioned in the AI-tool exposure surface.
06/19/20264 new articles

The story has broadened from general developer-workflow abuse into a more explicit supply-chain compromise of the developer toolchain itself, especially GitHub, VS Code, and package ecosystems. The new version emphasizes theft of reusable credentials and repository data as the main risk, rather than just exposed secrets or isolated malicious repositories.

  • Malicious VS Code extensions are now a primary compromise vector.
  • github.dev abuse is identified as a technical path to developer secrets.
  • npm, PyPI, and RubyGems are now part of the threat surface.
  • Incidents now include stolen vault data, not just API and cloud keys.
  • Coverage is now concentrated in June 2026.
05/12/2026Topic Formed

Recent reporting shows repeated attacks and exposures aimed at developer workflows, where fake advisories, malicious repositories, and vulnerable Next.js apps are used to steal credentials or deploy malware. Separate scanning research also finds widespread secret leakage in production JavaScript bundles, pointing to persistent weaknesses in how credentials are handled.