Over 100,000 repositories with malicious code have been identified on GitHub.
Security researchers from Apiiro have identified malicious activity where attackers post modified clones of various projects' repositories on GitHub. These clones include minor changes aimed at facilitating harmful actions. Typically, the malicious repository is created under the same name but attached to a different organization ("github.org/org1/proj" -> "github.org/org2/proj"), or with a slightly altered name (typosquatting), expecting that the victim […]
