Some GitHub projects have been targeted with malicious commits; a Texas researcher claims someone is impersonating him to make the submissions and smear him
Ax Sharma / BleepingComputer : X: @alexocheema , @evildojo666 , and @trubetech . Forums: r/cybersecurity X: Alex Cheema / @alexocheema : Backdoor attempt on @exolabs through an innocent looking PR. Read every line of code. Stay safu. [image] @evildojo666 : If you're looking for clarity about the Github backdoor attempts from November 12th: - someone is impersonating me - impersonator mad that i'm not giving them attention - i am sorry others are being dragged into it - taking a few hours off to work on my game again (priority) Brandon M. Trube / @trubetech : GitHub projects, including Exo Labs' repository, have faced malicious commits aimed at injecting backdoors and undermining researchers. This alarming trend raises critical questions about cybersecurity in the open-source community. Read more about it here: https://www.bleepingcomputer.com/ ... Forums: r/cybersecurity : GitHub projects targeted with malicious commits to frame researcher
Context & Ripple Effects
GitHub has repeatedly been used as a distribution and delivery channel for malicious code, from fake exploit repositories carrying malware to abuse by criminal and state-linked actors. This report narrows the risk to the contribution workflow itself: an apparently legitimate code submission can be paired with identity impersonation.
The alleged impersonation also resembles earlier campaigns in which attackers used researchers’ social identities to lend credibility to malicious material, as in fake proof-of-concept posts attributed to cybersecurity researchers. For maintainers, trust in both the patch and its purported author is at issue.
First-order effects
- Exo Labs and other targeted project maintainers must treat the reported submissions as potentially hostile, reviewing proposed changes line by line before merging and investigating contributor identity claims.
- The researcher said to be impersonated faces immediate reputational harm and must distinguish their real work from the alleged backdoor attempts.
Second-order effects
- Projects that rely on public pull requests may tighten review, signing, and contributor-verification practices, adding friction for legitimate first-time contributors.
- Attackers can exploit the social trust attached to known security researchers; maintainers therefore need to assess provenance alongside the code itself, not merely whether a contribution looks technically plausible.
Third-order effects
- If identity-linked malicious submissions persist, open-source security will increasingly depend on ecosystem-wide provenance and identity controls rather than repository-level code review alone.
- The pattern reinforces GitHub’s role as shared security infrastructure: abuse of code hosting, issue, and contribution channels can turn trust between maintainers and researchers into an attack surface.
The trend: This is part of a broader shift from malware hosted in public repositories toward attacks that exploit the trusted social and operational workflows around open-source code.