Github account compromised
pastebin.com
pastebin.com
Also recommend enabling 2 factor authentication.
That said, it kind of freaks me out in a good way. I'm glad github has this panel. People should be aware when several failed login attempts are made on their accounts.
There's literally no way my password was brute forced unless the adversary built a quantum computer, so I think this indicates that GitHub was attacked as opposed to the users directly.
It does sound like they might need to up their game on traffic monitoring, since how did the attacker get enough tries to brute force even a simple password? But that's why it's an arms race.
You block IPs that make too many fail attempts - you block an entire NAT range i.e. schools. Kids like to troll each other.
Alternatives?
I'd hope that github will do a post-mortem, and tell us what they know of the breaches.