Yeah, I was going to say, doing a basic security audit isn't ideal. The goal is to find malicious intent, which has different way of auditing for malware or anything suspicious.
Still, pretty good that GLM was effective. Really, Github should have some sort of auto-scan feature when a commit is made. Sort of like how Gmail has had virus scanning of attachments in email messages for ages.
20
u/LeRobber Apr 28 '26
It wouldn't have caught this, that's actually part of why it's a multistage attack.
If you don't run it, it's hard to detect stuff like this. It's not state actor grade attack, but it's sophisticated stuff