The Gentoo distribution replaced it GitHub mirror as it was allegedly lost control by someone who breached the code repository.
In one warning, the Gentoo project announced that the attacker managed to gain control of the Gentoo Github on June 28 at 11:20 AM Greek time.
"All Gentoo code hosted on github should be considered teased for now," says notice.
The Gentoo project has stated that its infrastructure is considered secure and that the users should be fine if they rsync or webrsync from gentoo.org.
A suspension in the gentoo-dev listings it states that the attacker replaced all portage and musl-dev trees with ebuilds that would attempt to remove all archives from the end user's system.
Although the malicious code should not work as GitHub is now restored, please do not use any ebuilds from the GitHub mirror acquired before 28 / 06 / 2018, 9: 00 (Greece time) until the next communication.
The distribution has not provided more details on how the attack took place.
__________________________________