Why GitHub's Security Team Lets Thousands of Malicious Repositories Spread
What does GitHub's security team even do?

I discovered thousands of GitHub repositories distributing Trojans using simple search patterns that anyone can replicate. Despite Microsoft's vast resources and AI capabilities, GitHub only removed the specific 10,000 repos I flagged, ignoring new ones appearing daily. This reactive approach raises serious questions about why a company with billions in revenue cannot proactively block this obvious malware scheme.
Microsoft is a corporation with billions in revenue. They have thousands of employees, limitless resources, and artificial intelligence. All they needed to do was allocate a few days for any regular employee so they could use Copilot to find all these repositories and block them.