Saturday, January 17, 2026
HomeGitHub

GitHub

GitHub Strengthens npm Security with Strict Authentication, Granular Tokens, and Trusted Publishing

GitHub has unveiled a comprehensive strategy to enhance npm’s security in response to a surge in malicious package registry attacks. Following the self-propagating Shai-Hulud worm that infiltrated popular JavaScript packages on September 14, the platform is rolling out a series of measures aimed at preventing...

New GhostAction Attack Exploits 327 GitHub Users Across 817 Repositories

Security researchers at GitGuardian have uncovered a sophisticated supply chain attack dubbed "GhostAction" that compromised 327 GitHub users across 817 repositories, successfully stealing 3,325 sensitive developer secrets. The attack, discovered on September 5, 2025, represents one of the largest documented cases of malicious GitHub...