Security
I keep my code on a box in my house. Ten thousand trojan repos on GitHub just made that look less paranoid.
A researcher just found 10,000 GitHub repos serving Trojan malware, cloned from real projects and wearing their real commit history as a disguise. Why 'it's on GitHub' stopped meaning 'it's fine', why vigilance is the wrong fix, and why my code lives on a box in my office.