// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-newsDTG 0600Z
Breach Record

GitHub

DISCLOSED 2026-08-06 · STOLEN CREDS

A GitHub account was breached and used to distribute credential-stealing malware through hundreds of npm packages. The attack represents a supply chain compromise leveraging stolen credentials. No details on the number of affected users or exact data exposed were provided.

The record

What we know

Disclosed
2026-08-06
Attack vector
Stolen Creds
Sector
Technology
Domain
github.com
Data classes exposed
credentials
ColdRecon assessment

Could a positive-security control have prevented this?

Verdict · unclear · opinion

The attack stemmed from a compromised account, not an endpoint change; a positive-security model on endpoints would not directly prevent account takeover.

Our assessments are opinion, grounded in the cited public facts. Read them critically.

Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the GitHub disclosure. It updates if new public reporting emerges. All tracked breaches →

GitHub just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →