Clean GitHub repo tricks AI coding agents into running malware

2026-06-28T13:23:28Z2f30da5d86c52e7d561f69f9192d3496f7056d124334dad8f7b918bd79897afc
account-takeoveractive-exploitationai-targetingbrowser-in-the-middleciscocredential-theftdomain-seizuregithubmacosmalwareopenai-impersonationphishingphishing-kitprompt-injectionrussian-aptsignalsim-swappingsupply-chainsupply-chain-compromise

What happened

Multiple high-risk campaigns and supply-chain attacks surfaced: a malicious GitHub repo can trick AI coding agents into executing hidden malware that evades scanners and human review; Russian-linked phishing is now stealing Signal backup recovery keys to access historical messages; CISA issued an urgent patch deadline for an actively exploited vulnerability in Cisco Unified Communications Manager Server; and a Polymarket frontend supply‑chain compromise led to ~$3M in customer losses. Additional threats include targeted OpenAI tenant impersonation to harvest sensitive data, macOS ‘Gaslight’ ev

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
2f30da5d86c52e7d561f69f9192d3496f7056d124334dad8f7b918bd79897afc
Enrichment time
2026-06-28T13:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.