Clean GitHub repo tricks AI coding agents into running malware

2026-06-28T07:23:31Zb2c57a7fed8e99678a342c330fb34fa0abe19d8ca7dc72ff665d5a3b3b0e6235
AI-assisted-attacksSIM-swapbrowser-in-the-middleciscocredential-theftfraudulent-identitymacOSmalwarephishingprompt-injectionsignalsupply-chain

What happened

Multiple active and evolving threats across software supply chains, phishing, and AI-assisted attack vectors were reported: CISA issued an urgent patch deadline for a Cisco Unified Communications Manager Server flaw being exploited in the wild; a supply‑chain injection stole ~$3M from Polymarket users; threat actors are using fraudulent OpenAI organization invites and abusing apps (Shop) to push callback phishing; Bluekit phishing-as-a-service added browser‑in‑the‑middle capabilities; Russian-linked actors are now stealing Signal backup recovery keys; a malicious GitHub repo can trick AI code‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
b2c57a7fed8e99678a342c330fb34fa0abe19d8ca7dc72ff665d5a3b3b0e6235
Enrichment time
2026-06-28T07:23:31Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Clean GitHub repo tricks AI coding agents into running malware · Baitaphish