๐๐ฐ๐ฉ๐ฏ ๐๐ช๐ญ๐ฆ๐ด
6.7K posts

๐๐ฐ๐ฉ๐ฏ ๐๐ช๐ญ๐ฆ๐ด
@JohnFiles_
๐๐ฆ๐ฏ๐ต๐ฆ๐ด๐ต๐ฆ๐ณ | ๐๐ฆ๐ค๐ฉ ๐๐ถ๐บ | ๐๐ต๐ฐ๐ณ๐บ ๐๐ช๐ฎ๐ฆ | ๐๐ฆ๐ฅ๐ข๐ค๐ต๐ฆ๐ฅ | ๐๐ฐ๐ง๐ง๐ฆ๐ฆ

TeamPCP actually open-sourced their own Shai-Hulud worm on GitHub under the MIT license >tracked as UNC6780 by Googleโs Threat Intelligence Group > from compromising a vulnerability scanner in March to breaching GitHubโs internal codebase in May > Each breach gave them credentials to fund the next attack. Thatโs not opportunistic hacking, thatโs a deliberate campaign with a clear endpoint target. GitHub was almost certainly the endgame from the start.

We are investigating unauthorized access to GitHubโs internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHubโs internal repositories (such as our customersโ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.




