Some Git source code repositories, including at least 392 from GitHub, have been wiped and replaced with a ransom demand in a possible coordinated attack
Hacker wipes Git repos and asks for Bitcoin. Gives victims 10 days and threatens to release the code.
Context & Ripple Effects
This 2019 incident is the opening move in what has become a recurring playbook against source-code hosting: attackers hit repositories where the code itself is the hostage. The demand — pay in Bitcoin within 10 days or the code is released — targeted at least 392 GitHub repos in what looked like a coordinated sweep rather than a single breach.
The pattern has since escalated along two tracks: covert tampering, seen in the repo confusion attack that cloned and malware-infected 100K+ repos, and direct extortion of named vendors — Grafana refused to pay after its GitHub environment was accessed, and Socket attributes both that breach and 20 waves of supply-chain attacks compromising 500+ software packages to TeamPCP.
First-order effects
- Owners of the wiped repos face an immediate binary: restore from local clones and mirrors if they exist, or negotiate a 10-day Bitcoin deadline with code release as leverage.
- GitHub hosts the largest known share of the damage — at least 392 of its repositories — putting it on the hook for incident response and user guidance while the attacker remains unidentified.
Second-order effects
- Every Git host and enterprise using hosted repos is forced to treat hosting-provider trust as insufficient, driving adoption of independent mirrors and off-platform backups as standard practice.
- The success of deletion-ransom here lowers the barrier for follow-on extortion of specific vendors — the path that later produced Grafana's ransom demand and its public refusal to pay.
Third-order effects
- If the pattern holds, source-code platforms shift from being trusted infrastructure to being attack surface in their own right, pushing the industry toward defense-in-depth across the whole repository ecosystem rather than per-account security.
- Ransom economics migrate from encrypting files to holding intangible assets — code, reputation, release pipelines — which later manifests as full supply-chain compromise like the Megalodon campaign infecting 5,500+ repos via automated commits.
The trend: Source-code repositories have evolved from collateral targets into primary ransom and supply-chain attack vectors, with each wave — deletion ransoms, repo cloning, vendor extortion, automated malware commits — raising the stakes for the entire Git hosting ecosystem.