Right now, there are thousands of repositories on GitHub distributing malware. Any of you can find these repositories, and you don’t need any special knowledge to do so. All you have to do is use the standard search function on the GitHub website.
These repositories have been around for
I imagine it’s because the GH Security team are responsible for the security of GH itself, not the million crappy repositories hosted there.
Rather, they ensure that the repos that are malware can’t compromise GH’s infrastructure and other repositories.