BTC $79,422.50 -0.61%
ETH $2,490.76 -0.38%
BNB $744.08 -1.76%
XRP $1.40 -1.38%
SOL $104.91 -1.40%
TRX $0.3362 +0.37%
DOGE $0.0896 -0.22%
ADA $0.2196 -0.63%
BCH $256.20 -1.72%
LINK $13.18 +7.39%
HYPE $87.82 -0.45%
AAVE $133.66 -1.27%
SUI $0.8137 +1.73%
XLM $0.1913 +2.57%
ZEC $1,196.48 +2.41%
BTC $79,422.50 -0.61%
ETH $2,490.76 -0.38%
BNB $744.08 -1.76%
XRP $1.40 -1.38%
SOL $104.91 -1.40%
TRX $0.3362 +0.37%
DOGE $0.0896 -0.22%
ADA $0.2196 -0.63%
BCH $256.20 -1.72%
LINK $13.18 +7.39%
HYPE $87.82 -0.45%
AAVE $133.66 -1.27%
SUI $0.8137 +1.73%
XLM $0.1913 +2.57%
ZEC $1,196.48 +2.41%

github

GitHub là một nền tảng lưu trữ mã nguồn dành cho các nhà phát triển, cung cấp chức năng kiểm soát phiên bản và hợp tác, dựa trên hệ thống kiểm soát phiên bản Git. Kể từ khi thành lập vào năm 2008, GitHub đã trở thành nền tảng cốt lõi cho các dự án mã nguồn mở và phát triển phần mềm, hỗ trợ lưu trữ mã nguồn, theo dõi vấn đề, quản lý dự án và các chức năng khác. Nó được ứng dụng rộng rãi trong lĩnh vực blockchain và tiền điện tử, nhiều mã nguồn và hoạt động phát triển của các dự án đều được công khai trên GitHub. Ảnh hưởng của GitHub thể hiện qua cộng đồng người dùng đông đảo và số lượng dự án, là một nguồn tài nguyên quan trọng cho cộng đồng các nhà phát triển.
Tất cả
Bài viết
Tin nhanh

Màn Sương: Phát hiện kho GitHub mô hình giả mạo Qwen, là bẫy phát tán phần mềm độc hại

Tin tức từ ChainCatcher, đội ngũ bảo mật SlowMist gần đây đã tiết lộ phát hiện một kho GitHub độc hại giả mạo "Qwen 3.8 27B mô hình định lượng cục bộ". Kho này tuyên bố rằng tệp mô hình phải vượt quá 16GB, trong khi nội dung tải về thực tế chỉ khoảng 487KB, chứa các tệp ngụy trang, trình thông dịch LuaJIT và các kịch bản Lua đã bị làm rối. SlowMist nhấn mạnh rằng dự án chính thức của Qwen không bị xâm nhập.Phân tích của SlowMist chỉ ra rằng, sau khi chương trình độc hại này chạy, nó sẽ thu thập thông tin máy chủ, chụp màn hình và gửi đến máy chủ C2 của kẻ tấn công; khi máy chủ mã hóa không còn hoạt động, nó sẽ đọc địa chỉ C2 dự phòng từ hợp đồng trên chuỗi Polygon, kẻ tấn công có thể xoay vòng cơ sở hạ tầng thông qua giao dịch trên chuỗi.Tải trọng tiếp theo có thể đánh cắp thông tin đăng nhập trình duyệt, Cookie, lịch sử, email, chứng chỉ WinSCP, Steam, cũng như các tệp và dữ liệu mở rộng liên quan đến ví tiền điện tử. SlowMist cũng phát hiện ra rằng, ít nhất 23 kho GitHub và 29 gói nén tương tự đã sử dụng cùng một chuỗi phát Lua.

GitHub gặp sự cố dịch vụ, tỷ lệ lỗi lưu lượng trên trang web và API khoảng 20%

Thông báo từ ChainCatcher, trang trạng thái chính thức của GitHub cho thấy, hiện tại nền tảng của họ đang trải qua sự cố dịch vụ, nhiều chức năng cốt lõi gặp phải sự giảm sút về khả năng sử dụng.Theo thông báo mới nhất, tỷ lệ lỗi trên trang web GitHub và yêu cầu API đã từng đạt khoảng 20%, tỷ lệ lỗi khi tải xuống kho lưu trữ và nội dung kho lưu trữ gốc khoảng 50%. Ngoài ra, xác thực danh tính SAML và OIDC, SCIM cũng như chức năng đồng bộ nhóm cũng bị ảnh hưởng.Hiện tại, các dịch vụ bị ảnh hưởng bao gồm: hiệu suất của Pull Requests giảm; hiệu suất của Issues giảm; hiệu suất của Actions giảm; hiệu suất của Webhooks giảm; yêu cầu API gặp sự cố; GitHub Copilot giảm khả năng sử dụng.GitHub cho biết, đội ngũ đang tiếp tục điều tra nguyên nhân gốc rễ của sự kiện này và sẽ cập nhật trạng thái thêm khi có thêm thông tin.Tính đến thời điểm hiện tại, GitHub vẫn chưa công bố nguyên nhân cụ thể của sự cố này, cũng như không cho biết liệu có liên quan đến sự cố an ninh hay không. Sự cố dịch vụ này có thể ảnh hưởng đến các nhà phát triển và người dùng doanh nghiệp phụ thuộc vào GitHub để lưu trữ mã, triển khai tích hợp liên tục và phát triển hỗ trợ AI.

Qubic GitHub bị xâm nhập, chính thức khẩn cấp nhắc nhở người dùng thực hiện các biện pháp an toàn

ChainCatcher thông báo, theo thông cáo từ tài khoản X chính thức của Qubic (@Qubic), tổ chức GitHub của Qubic đã xảy ra sự cố bảo mật vào ngày 13 tháng 7, một tài khoản bị xâm nhập đã truy cập vào kho mã và lấy thông tin nhạy cảm, chính thức đã can thiệp xử lý.Chính thức khuyến nghị các người dùng sau đây ngay lập tức hành động: Người bảo vệ mạng (Network Guardian) nên ngay lập tức thay đổi seed; Người dùng ví Web nếu đã mở khóa ví trong khoảng thời gian từ 03:00 đến 10:00 UTC hôm đó, hãy chuyển sang danh tính mới; nếu không chắc chắn về thời gian mở khóa lần cuối, cũng khuyến nghị chuyển đổi; Các nhà phát triển nên tạm ngừng kéo hoặc triển khai mã từ kho mã Qubic cho đến khi chính thức xác nhận hoàn thành kiểm toán.Chính thức cho biết, chi tiết đầy đủ và cập nhật tiếp theo sẽ được công bố trên kênh Discord chính thức, nhắc nhở người dùng không nên tin tưởng thông tin từ các kênh không chính thức, và cảnh báo bất kỳ ai không được yêu cầu seed của người dùng vì bất kỳ lý do gì. Báo cáo xử lý sự cố sẽ được công bố sau khi hoàn tất xử lý.

Slow Fog: Red Hat cloud service npm package suffers from active supply chain attacks, with stolen credentials found in over 300 GitHub repositories

SlowMist has issued a security alert, detecting an active npm supply chain attack targeting @redhat-cloud-services related packages. Currently, over 31 packages have been confirmed affected, with a weekly download volume of approximately 116,000 times, and stolen credentials exist in more than 300 GitHub repositories. This attack method is highly similar to the previous "Shai-Hulud" npm attack, including credential theft, creation of malicious repositories, and automated secret leakage. New suspicious repositories continue to emerge, indicating that the attack is still ongoing, and developers are still being continuously infected.Potential harms include: theft of GitHub/npm tokens, leakage of AWS/GCP/Azure cloud credentials, collection of SSH keys and Kubernetes secrets, leakage of local environment and wallet data, creation of malicious repositories and persistence operations, and even potentially destructive actions after tokens are revoked. It is recommended to immediately remove or downgrade affected @redhat-cloud-services package versions, conduct a comprehensive audit of CI/CD workflows and dependency installations, rotate all GitHub, npm, cloud service, SSH, and wallet-related keys, retain logs, and rebuild exposed developer machines or Runners from clean images while maintaining a high level of vigilance.

The security incidents at GitHub and Grafana are likely related to a large-scale "mini sandworm" supply chain attack

According to the threat intelligence released by Slow Fog, several high-frequency npm packages including AntV and Echarts-for-react, as well as the Python SDK durabletask, have recently been targeted by the Mini Shai-Hulud "mini sandworm" supply chain attack. The npm account atool was compromised, and the attacker automatically published 637 malicious versions within 22 minutes, affecting 317 packages. The attacker continuously uploaded durabletask versions 1.4.1, 1.4.2, and 1.4.3 within 35 minutes, bypassing normal release controls and impersonating an official Microsoft release.The large-scale leak of GitHub tokens and the ransomware attack on Grafana Labs are likely related to this supply chain attack. Affected components include high-frequency components such as AntV and Echarts-for-react in the npm ecosystem, as well as Python packages durabletask 1.4.1, 1.4.2, and 1.4.3. Attackers can steal cloud and local credentials, gain unauthorized access to internal repositories and sensitive cloud infrastructure, move laterally to developer machines and CI/CD pipelines, sell and exploit leaked GitHub tokens, and implement ransom and data leak threats.Slow Fog recommends immediately rotating all exposed credentials, replacing affected packages, isolating potentially infected systems, and implementing strict dependency review policies. Previously, it was reported that the "mini sandworm" worm had recently completed widespread infection in open-source code repositories, and developers should be vigilant in checking for issues.

GitHub updates security incident investigation: An employee's device was compromised, involving a contaminated VS Code extension

GitHub has updated the details of the investigation into the unauthorized access incident of its internal repositories: GitHub detected and contained an incident yesterday involving an employee's device being compromised, which involved a maliciously implanted VS Code extension. GitHub removed the malicious extension, isolated the affected terminals, and immediately initiated an incident response. Current assessments show that only GitHub's internal repositories experienced data exfiltration, and the approximately 3,800 repositories claimed by the attackers are roughly consistent with the investigation results. GitHub has prioritized rotating critical credentials, is analyzing logs, verifying credential rotations, and monitoring subsequent activities, with a complete report to be released after the investigation is concluded.Additionally, Slow Mist's Chief Information Security Officer 23pds commented on this incident, stating: "By analyzing leaks from cybercrime forums, hackers may have used Anthropic's Mythos security AI to precisely breach GitHub's defenses and steal information from about 4,000 core internal repositories: including the source code for Copilot, the algorithms for CodeQL, the Actions runtime, and the entire billing system. Further analysis of this code could lead to subsequent attacks, having a profound security impact on the integration of the open-source community."
app_icon
ChainCatcher Building the Web3 world with innovations.