Clean GitHub repo tricks AI coding agents into running malware

2026-06-28T01:23:27Z68218be63d1cc6f14d6d4256fd66399008bc03d74b323527277b1b592622cc16
ai-exploitationbrowser-in-the-middlecisaciscofraudmacosmalwareopenaiphishingsignalsim-swapsupply-chainthreat-actorsurgent-patchvulnerability

What happened

Multiple active and evolving threats reported: an attacker can craft a seemingly clean GitHub repo to trick AI coding agents into running hidden malware; Russian-linked phishers are now stealing Signal Backup Recovery Keys to access historical messages; CISA has ordered an urgent patching deadline for a Cisco Unified Communications Manager Server vulnerability that is being actively exploited. Other notable incidents include a $3M frontend supply-chain script injection at Polymarket, fraudulent OpenAI organization invites used to harvest corporate data, macOS “Gaslight” malware designed to obf

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
68218be63d1cc6f14d6d4256fd66399008bc03d74b323527277b1b592622cc16
Enrichment time
2026-06-28T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.