Clean GitHub repo tricks AI coding agents into running malware
2026-06-28T01:23:27Z•68218be63d1cc6f14d6d4256fd66399008bc03d74b323527277b1b592622cc16
ai-exploitationbrowser-in-the-middlecisaciscofraudmacosmalwareopenaiphishingsignalsim-swapsupply-chainthreat-actorsurgent-patchvulnerability
What happened
Multiple active and evolving threats reported: an attacker can craft a seemingly clean GitHub repo to trick AI coding agents into running hidden malware; Russian-linked phishers are now stealing Signal Backup Recovery Keys to access historical messages; CISA has ordered an urgent patching deadline for a Cisco Unified Communications Manager Server vulnerability that is being actively exploited. Other notable incidents include a $3M frontend supply-chain script injection at Polymarket, fraudulent OpenAI organization invites used to harvest corporate data, macOS “Gaslight” malware designed to obf
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 68218be63d1cc6f14d6d4256fd66399008bc03d74b323527277b1b592622cc16
- Enrichment time
- 2026-06-28T01:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.