HackSignal
    Thumbnail
    malware GitHub PyPI cryptocurrency

    AI Library Ultralytics Hit by Crypto Mining Malware in Supply Chain Attack

    December 07, 2024 • 1 min read

    Security researchers uncovered cryptocurrency mining malware embedded in two versions of the popular Ultralytics AI library on PyPI. The sophisticated attack exploited GitHub Actions to inject malicious code, prompting urgent calls for users to upgrade to the latest secure version.

    Thumbnail
    GitHub cybersecurity phishing

    Malicious GitHub Commits Target Security Researcher in Identity Fraud Attack

    November 16, 2024 • 1 min read

    Multiple open-source projects on GitHub were compromised by unauthorized code commits falsely attributed to security researcher Stephen Lacy. The attack exploited commit verification weaknesses to damage the researcher's reputation, prompting GitHub to investigate and the community to implement stricter authentication measures.

    Thumbnail
    cybersecurity GitHub hacking

    Critical Backdoor Attempt Detected in ExoLabs GitHub Repository

    November 14, 2024 • 1 min read

    A malicious pull request containing backdoor code was discovered in the popular ExoLabs GitHub repository, highlighting the growing threat of supply chain attacks. The incident serves as a crucial reminder for maintainers to implement strict code review protocols and security measures.

  • Previous
  • 1
  • 2