Hacker News new | ask | show | jobs
Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push (stepsecurity.io)
5 points by varunsharma07 95 days ago
1 comments

An attacker is compromising hundreds of GitHub accounts and injecting identical malware into hundreds of Python repositories. The earliest injections date to March 8, 2026, and the campaign is still active with new repos continuing to be compromised.