logo

Fake Linux leader using Slack to con devs into giving up their secrets

ID: 0b881b7a-a72f-5804-b511-055b8680ba49

STIX ID: report--0b881b7a-a72f-5804-b511-055b8680ba49

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2026-04-13

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

An attacker impersonated a Linux Foundation community leader in Slack to send a Google Sites phishing link that mimicked Google Workspace sign-in; victims were prompted to enter credentials and install a fake root certificate (malware) that enables interception of encrypted traffic, and macOS victims were directed to download and execute a binary (gapi) from IP 2.26.97.61. The campaign specifically targeted open-source projects (TODO, CNCF), poses a risk of credential theft and full system compromise, and follows other recent supply-chain/social-engineering attacks against developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.