What does GitHub's security team even do?

A security researcher demonstrates how easily malware-laden repositories can be found on GitHub using simple search queries. The author criticizes GitHub for failing to address these persistent security threats despite having significant resources.
Why it matters
It exposes vulnerabilities in major software hosting platforms and questions the efficacy of automated security measures in the developer ecosystem.
Right now, there are currently thousands of repositories on GitHub distributing malware. Any of you can find these repositories, and you don’t need any special knowledge to do so. All you have to do is use the standard search function on the GitHub website.
These repositories have been around for two years. GitHub has billions of dollars, a security team, and artificial intelligence. Why haven’t they solved this problem in two years?
First, we’ll look at the repositories we’ve already found, identify common patterns within them, and then use those patterns to find other repositories.
Take a look at these repositories; in each one, the readme contains a link to a zip archive containing a Trojan:
If we download this zip archive and submit individual files from it to VirusTotal, we’ll see the following results:
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in