logo

Hackers Abuse GitHub Issue Notifications to Phish Developers Through Malicious OAuth Apps

ID: 71be0341-d88e-5620-9efb-28cc7e5a509f

STIX ID: report--71be0341-d88e-5620-9efb-28cc7e5a509f

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-04-21

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

**Researchers uncovered a developer-targeted phishing campaign that leverages GitHub’s issue notification system and a TOCTOU race condition to send polished OAuth authorization links from GitHub no-reply emails.** Attackers create fake accounts and OAuth apps requesting broad repository and Actions permissions, mention targets in issues to trigger notifications, then rapidly edit or delete the issue so the email contains the malicious content while the repository shows no trace. If authorized, attackers can obtain access tokens to clone, modify, or backdoor code and interact with automation workflows, posing a supply-chain and account compromise risk; the report includes recommended defensive actions such as auditing OAuth apps, reviewing permissions, and restricting mentions in issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.