GitHub developers targeted by fake VS Code alerts spreading malware


  • Socket uncovers large-scale GitHub spam campaign abusing Discussions notifications
  • Fake reviews containing fake CVEs trick developers into downloading malware via cloud-hosted links
  • Thousands of identical posts observed, demonstrating a coordinated effort to target developer references and projects

Cybercriminals are tricking GitHub into sending fraudulent email notifications, tricking software developers into uploading malware, experts have warned.

Socket security researchers said they observed a large-scale, coordinated spam campaign targeting developers of various projects.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top