SIGNAL GRIDv0.1

Supply chain attack alert: .github/setup.js

1 sources1 storiesFirst seen 6/5/2026Score22Mixed Progress
Single Source
CoverageRecencyEngagementVelocityBignessConfidenceClipability
Bigness
22
Coverage
13
Recency
67
Engagement
8
Velocity
0
Confidence
49
Clipability
60
Polarization
0
Claims
1
Contradictions
0
Breakthrough
50

Sentiment Mix

Positive0%
Neutral100%
Negative0%

Geography

North America

Expert Signals

antihero

author1 mention

Hacker News

source1 mention

AI-Generated Claims

Generated from linked receipts; click sources for full context.

Vectors are* Claude hooks* Gemini hooks* Cursor setup* VScode tasksIt adds all of the above to execute node .github/setup.js, an obfuscated file.Check infected: `rg --hidden --no-ignore 'node .github/setup.js`It spreads by adding mimic'd skip-ci commits to open PRs which then get merged.Payload is obfuscated, available on request.If this is already a known one in the world, apologies, it hit us at around 10PM BST last night, the damage would have been incredible.Still trying to identify the original source.

Supported by 1 story

Related Events

Timeline (1 stories)

Jun 5 01:40 PMFirst
Supply chain attack alert: .github/setup.js
Hacker News26 engagement

Receipts (1)

Bias Snapshot

Center
Left 0%Center 100%Right 0%