Four Credential-Harvesting Campaigns Hit Open Source Ecosystems in Two Weeks
Blog post from GitGuardian
In May and June 2026, several coordinated cyber campaigns targeted developer environments and ecosystems, aiming to exfiltrate credentials by injecting malicious code into GitHub repositories, Composer packages, and software registries like npm, PyPI, and Crates.io. Notable campaigns included Megalodon, which affected over 5,500 GitHub repositories with backdoored commits, and Laravel-Lang, which involved rewriting Git tags in Composer packages to deploy a PHP credential stealer. Another campaign, TrapDoor, spanned multiple ecosystems, using tailored execution paths to steal credentials and inject disguised instructions into AI coding assistants. Miasma, an evolution of the Mini Shai-Hulud worm, compromised Red Hat npm packages by abusing trusted publishing processes. These attacks exploited readily accessible developer accounts and systems to access sensitive information without needing zero-day vulnerabilities, emphasizing the need for robust secrets security measures and the rotation of compromised credentials.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 9 | 2,515 | 393 | 134 | +17% |
| AI Coding Assistant | 2 | 2,161 | 541 | 167 | +20% |
| Kubernetes | 1 | 2,168 | 322 | 107 | +10% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.