
orchidfiles.com
July 26, 2026
4 min read
48/100
Summary
Thousands of repositories on GitHub are currently distributing malware, accessible through the standard search function without special knowledge. Despite having a substantial budget, a dedicated security team, and AI resources, GitHub has not resolved this issue over the past two years.
Key Takeaways
Community Sentiment
Positives
Concerns

I found 10k GitHub repositories distributing Trojan malware
Jun 18, 2026

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories
Mar 15, 2026

Microsoft's stance on zero day exploits is a dumpster fire of their own making
May 28, 2026

Restructuring GitHub's bug bounty program
Jul 23, 2026

Anatomy of a Failed (Nation-State?) Attack
Jun 27, 2026