Home / Companies / GitGuardian / Blog / Post Details
Content Deep Dive

Four Credential-Harvesting Campaigns Hit Open Source Ecosystems in Two Weeks

Blog post from GitGuardian

Post Details
Company
Date Published
Author
Anna Nabiullina
Word Count
642
Company Posts That Month
15
Language
English
Hacker News Points
-
Post removed?
No
Summary

In May and June 2026, several coordinated cyber campaigns targeted developer environments and ecosystems, aiming to exfiltrate credentials by injecting malicious code into GitHub repositories, Composer packages, and software registries like npm, PyPI, and Crates.io. Notable campaigns included Megalodon, which affected over 5,500 GitHub repositories with backdoored commits, and Laravel-Lang, which involved rewriting Git tags in Composer packages to deploy a PHP credential stealer. Another campaign, TrapDoor, spanned multiple ecosystems, using tailored execution paths to steal credentials and inject disguised instructions into AI coding assistants. Miasma, an evolution of the Mini Shai-Hulud worm, compromised Red Hat npm packages by abusing trusted publishing processes. These attacks exploited readily accessible developer accounts and systems to access sensitive information without needing zero-day vulnerabilities, emphasizing the need for robust secrets security measures and the rotation of compromised credentials.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 9 2,515 393 134 +17%
AI Coding Assistant 2 2,161 541 167 +20%
Kubernetes 1 2,168 322 107 +10%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.