Right now, there are thousands of repositories on GitHub distributing malware. Any of you can find these repositories, and you don’t need any special knowledge to do so. All you have to do is use the standard search function on the GitHub website.
These repositories have been around for
Not much. In my experience, they will only take action if it’s obvious. I’ve reported a project three times that is serving malware, but they won’t take it down because it’s using a custom .npmrc and the deps hosted there have the malware. It’s easy to see after npm installing, but they don’t seem to want to do that much investigating.