Clean GitHub repo tricks AI coding agents into running malware
2026-06-27T19:23:28Z•ece80080d36975634b7ea7ac8fd9849f07917bf2743ecfe0ce8e6a2cd2061667
active-exploitationai-agent-malwarebackup-recovery-keysbluekitbrowser-in-the-middlecisco-unified-communicationscrypto-theftdomain-seizureevasiongithub-repomacos-gaslightopenai-impersonationphishingpolymarketsignalsim-swappingsupply-chain-attackwindows-10-esu
What happened
Multiple high-impact threats and techniques observed across the ecosystem: AI coding agents can be tricked into executing malware hidden in otherwise benign GitHub repos; Russian-linked phishing campaigns are now targeting Signal Backup Recovery Keys to access historical messages; CISA issued an urgent patch deadline for an actively exploited vulnerability in Cisco Unified Communications Manager Server; a third‑party supply‑chain injection caused Polymarket to lose ~$3M in customer funds; threat actors are using fraudulent OpenAI organization invites to harvest company data; macOS ‘Gaslight’ (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- ece80080d36975634b7ea7ac8fd9849f07917bf2743ecfe0ce8e6a2cd2061667
- Enrichment time
- 2026-06-27T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.