GitHub has been hit by a large-scale repo confusion campaign in which attackers fork legitimate projects, keep names and appearances close to the originals, and inject heavily obfuscated malicious code intended to steal passwords, cryptocurrency wallets, and other developer secrets. Apiiro reported that the operation was largely automated and tied to more than 100,000 infected repositories, while Ars Technica said the broader attack generated millions of malicious repositories and exploited the difficulty users face distinguishing authentic projects from poisoned forks.
Multiple GitHub repositories later carried security issues warning that malicious code had been injected via compromised accounts, including projects such as django-restful-admin, ImportNURBS, siriraj-assist, ood_coverage, issued, and bottom-up-attention-vqa. The notices indicate the campaign was not limited to fake lookalike repos but also reached legitimate codebases through account compromise, extending the supply-chain risk to developers who clone, fork, or build from affected repositories while GitHub continues removing abusive content through reporting, manual review, and machine-learning-based detection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Security issues were opened across several GitHub repositories warning that malicious code had been injected via compromised accounts. Repositories named in the references include KeithSloan/ImportNURBS, biodatlab/siriraj-assist, BierOne/ood_coverage, metalogico/issued, and BierOne/bottom-up-attention-vqa.
A similar GitHub security issue was opened for amirasaran/django-restful-admin, indicating malicious code had been injected into the repository through a compromised account. This shows the campaign or related compromises continued to surface in additional repositories after the March disclosures.
Ars Technica reported on the ongoing campaign, citing Apiiro's findings that attackers had created millions of malicious forks impersonating legitimate repositories. The report said the malware was designed to steal passwords and cryptocurrency and noted GitHub was removing many, but not all, abusive repositories.
Apiiro researchers uncovered a large-scale campaign in which attackers forked legitimate GitHub repositories and injected obfuscated malware. The company said the operation affected more than 100,000 repositories and relied on repository confusion to trick developers into downloading infected code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcearstechnica.com
Open sourceapiiro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.