10,000 fake GitHub repos are pushing malware. Here's how to spot one
A June 2026 campaign cloned 10,000 GitHub repos with real commit history and contributor names, then hid malware behind a README download link. Here's how it works and how to not get burned.