
orchidfiles.com
June 18, 2026
8 min read
75/100
Summary
A large-scale malware distribution campaign on GitHub has been identified, involving 10,000 repositories that distribute Trojan malware. These repositories originate from different contributors and share a common pattern, enabling the creation of a script to find them.
Key Takeaways
Community Sentiment
Positives
Concerns

What does GitHub's security team even do?
Jul 26, 2026

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
Mar 15, 2026

Config Files That Run Code: Supply Chain Security Blindspot
Jun 8, 2026

Anatomy of a Failed (Nation-State?) Attack
Jun 27, 2026

GitHub's Fake Star Economy
Apr 20, 2026