GitHub Developers Targeted by Fake VS Code Alerts Spreading Malware



  • Socket discovers large-scale spam campaign on GitHub abusing “Discussions” notifications
  • Fake advisories with fake CVEs trick developers into downloading malware via cloud-hosted links
  • Thousands of identical posts were observed, showing a coordinated effort to target developers’ credentials and projects.

Experts have warned that cybercriminals are tricking GitHub into sending fraudulent email notifications, luring software developers to download malware.

Socket security researchers, who said they observed a large-scale coordinated spam campaign targeting developers across multiple projects.



Leave a Comment

Your email address will not be published. Required fields are marked *