It appears as though the attackers behind the Nx supply chain attack on Wednesday are now using leaked GitHub tokens to make private GitHub repositories public (and renaming them to s1ngularity-repository-XXXXX in the process). 7.2k repositories affected at time of writing.
https://xcancel.com/adnanthekhan/status/1961152614055207039
fennec-posix•1h ago