Clever 'GitHub Scanner' campaign abusing repos to push malware (www.bleepingcomputer.com)
from kid@sh.itjust.works to cybersecurity@sh.itjust.works on 19 Sep 2024 12:46
https://sh.itjust.works/post/25415173

#cybersecurity

threaded - newest

treadful@lemmy.zip on 19 Sep 2024 19:19 collapse

A malicious GitHub user opens a new “issue” on an open source repository falsely claiming that the project contains a “security vulnerability” and urges others to visit a counterfeit “GitHub Scanner” domain. The domain in question, however, is not associated with GitHub and tricks users into installing Windows malware.

It’s really not that clever.