Hacker News new | ask | show | jobs
by heartbreak 1520 days ago
For what it's worth, elsewhere in this comment section someone posted that Github Support says the zip downloads weren't related to this incident. Reading between the lines, the compromised repos were probably accessed using normal git clone actions.
1 comments

That was me who posted that :) seems unrelated, but still hoping to get that figured out anyway.