Identify compromised versions of GitHub apps using JupiterOne

JupiterOne Team
•
Jan 31st, 2023

Written by Brendan Quinn and Yvie Djieya

‍On January 30, 2023 GitHub disclosed that unauthorized users had gained access to repositories that contained encrypted code signing certificates for its Desktop and Atom applications. These certificates were password protected and there is no current evidence of malicious use, according to GitHub, but customers are still advised to take precautions before impacted certificates are deprecated.

As a preventative measure, GitHub will be deprecating the Mac and Windows signing certificates used to sign Desktop app versions 3.0.2-3.1.2 and Atom versions 1.63.0-1.63.1 on Thursday, February 2, 2023. Once deprecated, these certificates can no longer be used to sign code. GitHub recommends updating Desktop and/or downgrading Atom before February 2nd to avoid workflow disruptions.

The following J1 queries can be used to help identify which devices in your environment have the compromised versions of the application installed:

‍

GitHub Desktop

FIND Application WITH displayName ~= ('GitHub' OR 'Github') AS x 
THAT INSTALLED AS r (Device|Host) AS y 
WHERE r.version = ('3.1.2' OR '3.1.1' OR '3.1.0' OR '3.0.8' OR '3.0.7' OR '3.0.6' OR '3.0.5' OR '3.0.4' OR '3.0.2')
RETURN 
x.displayName AS GitHub_Desktop_App,
r.version AS Compromised_Version,
r._class AS Is, 
y.displayName AS On, 
y.email AS Owned_By

GitHub Atom

FIND Application WITH displayName ~= ('Atom.app') AS x 
THAT INSTALLED AS r (Device|Host) AS y 
WHERE r.version = ('1.63.1' OR '1.63.0')
RETURN 
x.displayName AS GitHub_Desktop_App,
r.version AS Compromised_Version,
r._class AS Is, 
y.displayName AS On, 
y.email AS Owned_By

‍

New call-to-action

Other articles

Technical debt, an expanding remit, and ungoverned AI agents are reshaping CISO governance in 2026. Here's what's changing and what closes the gap.

John Le
•
Sep 25th, 2026
  • CCM
  • CAASM

AI agents and third-party models are expanding your attack surface. Here's what's changing in supply chain security and machine identity — and what closes the gap.

John Le
•
Sep 14th, 2026
  • CAASM
  • SBOM
  • AI ASM
  • IAM
The Top CAASM Tools in 2026

Here's what actually matters when you evaluate a CAASM platform, plus how the top vendors compare in 2026.

John Le
•
Sep 3rd, 2026
  • CAASM

Tools are silent.
Risks aren't.

See your full security program as one connected picture in a 30-minute demo tailored to your environment.