Attackers Target GitHub Developer Workflows
Coverage from shattered.io, KrebsOnSecurity, and others

Attackers are abusing GitHub repositories, Discussions, VS Code workflows, JavaScript bundles, and vulnerable web applications to steal credentials or deliver malware.
The activity combines social engineering, repository impersonation, supply-chain compromise, exploitation of exposed secrets, and automated attacks against internet-facing software. The common risk is that trusted developer infrastructure and application artifacts can provide access to source code, cloud environments, accounts, and downstream users.
The story now places greater emphasis on active credential theft and supply-chain compromise across more delivery vectors, while tightening some details around the campaigns and affected artifacts. The Next.js exploitation remains central, but the reporting now more clearly frames developer infrastructure, malicious packages, and application bundles as interconnected attack paths.
The story has broadened from general GitHub-related secret theft and malware activity into a more specific set of attack paths against developer tooling, web applications, and build artifacts. The new version adds concrete campaign details, including a VS Code zero-day, fake GitHub repository impersonation, and large-scale token and secret harvesting.
