GitHub developers targeted by fake VS Code alerts that spread malware


  • Socket Reveals Large-scale GitHub Spam Campaign Abusing “Discussions” Messages
  • Fake messages with fake CVEs trick developers into downloading malware via cloud-hosted links
  • Thousands of identical posts observed, showing coordinated efforts to target developer credentials and projects

Cybercriminals are tricking GitHub into sending out fraudulent email notifications and luring software developers into downloading malware, experts have warned.

Security researchers Socket, who said they observed a large-scale, coordinated spam campaign targeting developers on various projects.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top