Microsoft which owns GitHub, has been washing their hands if any responsibility in helping to resolve the ongoing supply chain catastrophe which is hosted and spread nearly entirely via Github repositories: not responding to security researchers flagging malware hosted on GitHub; doing nothing to address the proliferation of open source malware across their platform, giving no recourse for action, not applying their tremendous resources to the problem, fiddling as the open source community burns and leaving the devs to fend for themselves. Let's not mention the recent very hostile and trust-erodibg behavior towards bug bounty security researchers.
The *&$@ finally spread all the way up to the top of the hill in a compromise of Microsoft's own repos, which I think highlights the scale of the problem.
And in response, they offer a watery corporate platitude, "a few customers were affected in a recent incident, and we're looking into it."