Switch language한국어
Back to the list

Major phishing campaign on GitHub using fake security alerts

TL;DR AI

Key summary

2 min read
  1. A large-scale phishing campaign is abusing GitHub Discussions to post fake Visual Studio Code security alerts that urge users to install updates via external links.

  2. Thousands of nearly identical messages are posted across many repositories in minutes by newly created or barely active accounts, with large numbers of developers tagged to increase visibility.

  3. The posts cite fictitious CVE identifiers and attackers impersonate well-known maintainers or security researchers to appear trustworthy.

  4. External links (often to Google Drive) redirect through chains to attacker-controlled infrastructure where a JavaScript profiling page collects time zone, browser and operating system data.

  5. The profiling data is forwarded to a command-and-control server to filter real victims from bots and researchers; no direct malware page or credential collection is present at this stage.

Read the original