CodeQL - Tool

Threat entity extracted from intelligence sources

Frequency
3
occurrences
First Seen
April 28, 2026
Last Seen
July 12, 2026

CodeQL is a tool tracked by ThreatCluster, appearing in 4 threat clusters built from 3 intelligence report mentions.

CodeQL is a tool tracked across 4 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 28, 2026; most recent activity July 12, 2026.

Related Threat Clusters

Recent Intelligence Reports

  • Spoofed Git Identity Ai Code Reviewer — www.manifold.security · July 12, 2026
  • GitHub updates security incident investigation: An employee's device was compromised ... — Panewslab · May 20, 2026
  • PyPI has completed its second audit – The Python Package Index Blog — blog.pypi.org · April 28, 2026

Frequently asked questions

What is CodeQL?

CodeQL is a tool tracked by ThreatCluster, appearing in 4 threat clusters built from 3 intelligence report mentions.

Is CodeQL still active?

The most recent intelligence report mentioning CodeQL on ThreatCluster is dated July 12, 2026. Activity was first observed April 28, 2026, giving a tracked span from then to July 12, 2026.

What is CodeQL associated with?

Across ThreatCluster reporting, CodeQL most frequently co-occurs with Data Breach, Malware, Prompt Injection, Supply Chain Attack, Cline Supply Chain Compromise, among 12 tracked related entities.

What are the latest developments involving CodeQL?

The most significant recent cluster is “GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension” (149 articles · Updated May 20, 2026). CodeQL appears across 4 threat clusters in total, listed above with sources.

How much reporting does ThreatCluster have on CodeQL?

CodeQL appears in 3 intelligence report mentions across 4 deduplicated threat clusters, aggregated from 17,000+ monitored sources.

CVSS v3.1 Breakdown