History
07/25/20260 new articles
The story now places greater emphasis on active credential theft and supply-chain compromise across more delivery vectors, while tightening some details around the campaigns and affected artifacts. The Next.js exploitation remains central, but the reporting now more clearly frames developer infrastructure, malicious packages, and application bundles as interconnected attack paths.
07/24/20260 new articles
The story has broadened from general GitHub-related secret theft and malware activity into a more specific set of attack paths against developer tooling, web applications, and build artifacts. The new version adds concrete campaign details, including a VS Code zero-day, fake GitHub repository impersonation, and large-scale token and secret harvesting.
- VS Code zero-day in github.dev can expose broadly scoped GitHub OAuth tokens.
- Hundreds of fake GitHub repositories impersonated legitimate software.
- More than 42,000 tokens were found in JavaScript bundles.
- Automated Next.js exploitation harvested secrets from at least 766 hosts.
- Fake security alerts used GitHub Discussions and fabricated CVEs.
07/24/20264 new articles
The story has widened from repeated developer-supply-chain credential theft into a more explicit GitHub-centered security campaign that now includes public monitoring, takedowns, and broader incident handling issues. The current version also adds new actors and a stronger emphasis on disclosure failures and operational response.
- GitHub is expanding public monitoring and secret-scanning controls.
- CISA appears as a newly exposed government victim and later commentator.
- GitHub.dev and repository Discussions are now cited as attack paths.
- Disclosure handling problems include delayed remediation and rejected reports.
- GitHub Agentic Workflows are newly mentioned in the AI-tool exposure surface.
06/19/20264 new articles
The story has broadened from general developer-workflow abuse into a more explicit supply-chain compromise of the developer toolchain itself, especially GitHub, VS Code, and package ecosystems. The new version emphasizes theft of reusable credentials and repository data as the main risk, rather than just exposed secrets or isolated malicious repositories.
- Malicious VS Code extensions are now a primary compromise vector.
- github.dev abuse is identified as a technical path to developer secrets.
- npm, PyPI, and RubyGems are now part of the threat surface.
- Incidents now include stolen vault data, not just API and cloud keys.
- Coverage is now concentrated in June 2026.
05/12/2026Topic Formed
Recent reporting shows repeated attacks and exposures aimed at developer workflows, where fake advisories, malicious repositories, and vulnerable Next.js apps are used to steal credentials or deploy malware. Separate scanning research also finds widespread secret leakage in production JavaScript bundles, pointing to persistent weaknesses in how credentials are handled.