Risky Bulletin Newsletter
March 23, 2026
Risky Bulletin: GitHub is starting to have a real malware problem
Presented by
News Editor
GitHub is slowly becoming a very dangerous website as more and more threat actors are starting to use it to host and distribute malware disguised as legitimate software repositories.
What started as an infrequent sighting in early 2024 is now at the center of an increasing number of infosec and malware reports.
The tactic is usually the same. A threat actor would take a legitimate repository, add malware to the files—typically an infostealer or a remote access trojan— and then upload the boobytrapped repo back on GitHub.