- Sources: follow-up post, June write-up, HN 49061769
- Summary: A post dated 2026-07-26 on orchidfiles.com follows up the author's June write-up that the 2026-06-18 digest covered, and states that after that article published a script and a list of about 10,000 repositories whose README linked to a zip archive containing a Trojan, GitHub deleted all of them within a few hours and took no further action, while repositories the author found hours later and appended to the same article are still not blocked a month on. The post gives three reproducible GitHub code-search queries against README download headings and against links to version-numbered zip archives on raw.githubusercontent.com, and reports that the result counts GitHub returns for the same query move between 111 and 4,400. The counts and the claim of inaction are the author's own observations, and GitHub has not responded.
- Why it matters: The delivery channel is GitHub's own code search, so the exposed party is any developer who searches for a tool and follows a README download link, and the reported remediation was takedown of a supplied list rather than detection of the pattern that produced it.
- Follow-up: Watch for a GitHub response and for whether the reported search queries stop returning unblocked repositories.
send feedback on this story