/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Some Git source code repositories, including at least 392 from GitHub, have been wiped and replaced with a ransom demand in a possible coordinated attack

Hacker wipes Git repos and asks for Bitcoin.  Gives victims 10 days and threatens to release the code.

ZDNet Catalin Cimpanu

Context & Ripple Effects

This 2019 incident is the opening move in what has become a recurring playbook against source-code hosting: attackers hit repositories where the code itself is the hostage. The demand — pay in Bitcoin within 10 days or the code is released — targeted at least 392 GitHub repos in what looked like a coordinated sweep rather than a single breach.

The pattern has since escalated along two tracks: covert tampering, seen in the repo confusion attack that cloned and malware-infected 100K+ repos, and direct extortion of named vendors — Grafana refused to pay after its GitHub environment was accessed, and Socket attributes both that breach and 20 waves of supply-chain attacks compromising 500+ software packages to TeamPCP.

First-order effects

  • Owners of the wiped repos face an immediate binary: restore from local clones and mirrors if they exist, or negotiate a 10-day Bitcoin deadline with code release as leverage.
  • GitHub hosts the largest known share of the damage — at least 392 of its repositories — putting it on the hook for incident response and user guidance while the attacker remains unidentified.

Second-order effects

  • Every Git host and enterprise using hosted repos is forced to treat hosting-provider trust as insufficient, driving adoption of independent mirrors and off-platform backups as standard practice.
  • The success of deletion-ransom here lowers the barrier for follow-on extortion of specific vendors — the path that later produced Grafana's ransom demand and its public refusal to pay.

Third-order effects

  • If the pattern holds, source-code platforms shift from being trusted infrastructure to being attack surface in their own right, pushing the industry toward defense-in-depth across the whole repository ecosystem rather than per-account security.
  • Ransom economics migrate from encrypting files to holding intangible assets — code, reputation, release pipelines — which later manifests as full supply-chain compromise like the Megalodon campaign infecting 5,500+ repos via automated commits.

The trend: Source-code repositories have evolved from collateral targets into primary ransom and supply-chain attack vectors, with each wave — deletion ransoms, repo cloning, vendor extortion, automated malware commits — raising the stakes for the entire Git hosting ecosystem.