Mantine-datatable (and others) compromised – owner account suspended
What they're not telling you: GitHub's Security Breach Leaves Open-Source Maintainers Exposed While Platform Remains Silent A Romanian open-source developer lost control of his GitHub account after unauthorized malicious commits were pushed to his repositories, and nearly 20 hours later the poisoned code remained live while the platform's support system offered no timeline for recovery. Ionut Colceriu, who maintains the popular Mantine-datatable library and four other repositories, discovered on June 4, 2026 that his account had been compromised. According to a statement posted by his wife, Irinel-Ramona Colceriu, because Ionut himself was locked out, unauthorized commits bearing the message "chore: update dependencies [skip ci]" were injected into his repositories via the github-actions bot.
What the Documents Show
The actual payload—a malicious script named node .github/setup.js—would execute when developers opened the source code in VS Code, Cursor, or other AI-assisted coding environments, or when they ran npm test. The Colceriu statement identifies a potential source: GitHub's own infrastructure may have been compromised as part of what she describes as "the broader GitHub infrastructure breach carried out by the TeamPCP hacking group in May 2026." That claim has not been independently verified from official GitHub sources in the material provided. What is documented is that Ionut filed support ticket with GitHub and received no substantive response within 20 hours of the incident—a critical window during which the malicious code remained accessible in active repositories. The technical scope appears contained. According to Irinel-Ramona's statement, GitHub's own investigation found "no traces of compromise" in their environments, and critically, "the published npm packages are completely safe." This distinction matters: developers who installed Mantine-datatable or the other affected libraries via npm package manager are not at risk.
Follow the Money
The danger exists only for developers who cloned or pulled the repositories directly from GitHub and then opened the source code in development environments. However, the response from GitHub itself has been what Irinel-Ramona describes as "slow and dehumanizing." A legitimate open-source maintainer, locked out of an account he built over years, had no direct contact with GitHub support, no timeline for account recovery, and no mechanism to protect his own users—all while malicious code remained in repositories bearing his name. The statement notes that "GitHub's support process during a security incident is, frankly, slow." This is not speculation about GitHub's procedures; it is a documented account of what one user experienced in real time. The Mantine-datatable library itself has 1.2k stars on GitHub and is actively maintained. Its compromise, even limited to source repositories, represents a supply-chain attack vector that could theoretically reach any developer who works directly with the source code. The fact that the malicious commits remained uncorrected for nearly a day—not because the developer was negligent, but because he was locked out of his own account—raises questions about GitHub's incident response protocols and whether the platform has adequate procedures for restoring legitimate developer access during active security incidents.
Primary Sources
- Source: Hacker News
- Category: Unexplained
- Cross-reference independently — don't take our word for it.
Disclosure: NewsAnarchist aggregates from public records, API feeds (Federal Register, CourtListener, MuckRock, Hacker News), and independent media. AI-assisted synthesis. Always verify primary sources linked above.