Clean GitHub repo tricks AI coding agents into running malware
2026-06-28T13:23:28Z•2f30da5d86c52e7d561f69f9192d3496f7056d124334dad8f7b918bd79897afc
account-takeoveractive-exploitationai-targetingbrowser-in-the-middleciscocredential-theftdomain-seizuregithubmacosmalwareopenai-impersonationphishingphishing-kitprompt-injectionrussian-aptsignalsim-swappingsupply-chainsupply-chain-compromise
What happened
Multiple high-risk campaigns and supply-chain attacks surfaced: a malicious GitHub repo can trick AI coding agents into executing hidden malware that evades scanners and human review; Russian-linked phishing is now stealing Signal backup recovery keys to access historical messages; CISA issued an urgent patch deadline for an actively exploited vulnerability in Cisco Unified Communications Manager Server; and a Polymarket frontend supply‑chain compromise led to ~$3M in customer losses. Additional threats include targeted OpenAI tenant impersonation to harvest sensitive data, macOS ‘Gaslight’ ev
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 2f30da5d86c52e7d561f69f9192d3496f7056d124334dad8f7b918bd79897afc
- Enrichment time
- 2026-06-28T13:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.