Github under siege: malware, outages, and a system on the brink

GitHub is facing a crisis of unprecedented scale, grappling with a deluge of malware, persistent service disruptions, and a growing sense of alarm within the developer community. The platform, once a cornerstone of open-source development, is now reportedly riddled with malicious code, impacting everything from Python tools like LiteLLM to core infrastructure.

A torrent of trouble: from vulnerabilities to widespread malware

Recent security vulnerabilities have unleashed a wave of malware onto the platform, transforming GitHub into a veritable repository of digital threats. This isn't a theoretical concern; evidence suggests malicious code is actively being integrated into projects, posing a significant risk to users and their systems. The situation is rapidly escalating, creating a scenario where even established tools are becoming potential backdoors.

Service collapse & a critical admission

Service collapse & a critical admission

Adding fuel to the fire, GitHub is experiencing ongoing and increasingly frequent service outages. While the company attributes these disruptions to rapid user growth, the underlying issues appear far more complex. GitHub officially acknowledges a “serious infrastructure problem”, admitting they require a “fundamental architectural overhaul” to address the cascading failures plaguing their services – effectively admitting their current system is buckling under the strain. The fact that core functions are routinely unavailable is a deeply troubling sign.

Growth as a liability

Growth as a liability

According to Vladimir Fedorov, GitHub’s CTO, the surge in activity – a ‘growth of extreme speed’ – is directly linked to the current instability. It's a brutal realization for a company that’s predicated its success on accessibility and widespread adoption. Essentially, the platform’s meteoric rise has exposed fundamental limitations in its design and scalability. It’s become a textbook example of success outpacing infrastructure.

The api bottleneck

The api bottleneck

The initial triggers for the outages were traced back to a significant surge in API traffic – reportedly more than tenfold the usual volume – following updates from popular applications released in early February. This overload exposed vulnerabilities in GitHub’s filtering and blocking mechanisms, allowing malicious actors to flood the system with requests and compromised code. The consequences have been devastating, with error rates peaking at a chilling 99% in Copilot Coding Agent.

Architectural reckoning

Architectural reckoning

Jakub Oleksy, VP of Engineering, has been blunt: