Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign
ID: 4fe49714-96c6-51d9-a699-ea912dbc0d3f
STIX ID: report--4fe49714-96c6-51d9-a699-ea912dbc0d3f
Feed Name: cybersecurityNews.com
A large-scale phishing campaign flooded GitHub Discussions with fake Visual Studio Code security advisories that urged developers to download a "patched" version via external links; links routed victims through Google share endpoints and attacker infrastructure (notably drnatashachinn.com) where browser fingerprinting and obfuscated JavaScript profiled users before delivering malware or phishing payloads. The posts used newly created/low-activity accounts, mass-tagging, and fabricated CVEs to amplify reach and exploit GitHub's notification system; developers are advised to only obtain VS Code updates from official Microsoft channels and report suspicious Discussions to GitHub.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
