Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Clever 'GitHub Scanner' campaign abusing repos to push malware #149

Open
hasecilu opened this issue Sep 20, 2024 · 3 comments
Open

Clever 'GitHub Scanner' campaign abusing repos to push malware #149

hasecilu opened this issue Sep 20, 2024 · 3 comments

Comments

@hasecilu
Copy link
Collaborator

hasecilu commented Sep 20, 2024

Caution

Basically I got an pishing email which apparently leads to Lumma Stealer information-stealing malware, the interesting thing is that they used GitHub notification system to make it seem legit, <<< Issue #147 >>>.

Important

I think the users that are subscribed to the repo are also notified, so be careful, don't click suspicious links and don't copy-paste commands on the terminal.

Anyway, read the article attached below to know more about it.

Hey there!

We have detected a security vulnerability in your repository. Please contact us at h t t p s : / / github-scanner [dot] shop to get more information on how to fix this issue.

Best regards,
Github Security Team


News article: https://www.bleepingcomputer.com/news/security/clever-github-scanner-campaign-abusing-repos-to-push-malware/
Virus total URL analysis: https://www.virustotal.com/gui/url/3413e5b9178cc96a7246ee2c9fc4e84756e4911a521a40c450c51bd8eafb89e2/detection

@Finii
Copy link
Collaborator

Finii commented Sep 20, 2024

Thanks for sharing.

I assume you deleted Issue 147? How did you do that? I remember some other spam in another repo and I could not delete it - but that is possibly because I'm too stupid :-D

@Freddywhest
Copy link

Man, this issue is rampant across almost all public repos on GitHub.

@hasecilu
Copy link
Collaborator Author

I assume you deleted Issue 147? How did you do that? I remember some other spam in another repo and I could not delete it - but that is possibly because I'm too stupid :-D

Actually not, probably was GitHub, when i clicked the view it on GitHub link the issue was gone

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

3 participants