Github Security: Repeated Unauthorized Automated Force‑Pushes Rewriting Lat #189594
Unanswered
Abhishek1350
asked this question in
Repositories
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
General
Body
Summary
I am reporting an ongoing security incident involving repeated unauthorized automated pushes to my GitHub repositories. Malicious code is being injected by amending the latest commit and force‑pushing it, which causes the changes to always appear as the most recent commit on the default branch.
These pushes are not initiated from any of my local environments and continue even after full credential and integration revocation.
Observed Behavior
The unauthorized commits follow a consistent pattern that matches an automated script which:
As a result, the commit history is rewritten and the malicious changes always appear as the latest commit. even in private repos that don't even have contributers, also in repose where i'm a contributer.
Remediation Already Completed
Despite completing all of the above, unauthorized automated force‑pushes continue.
Impact and Scope
Request for GitHub Security Team
I am requesting a security escalation and backend investigation, including:
Beta Was this translation helpful? Give feedback.
All reactions