GitHub Issue Alerts Exploited in OAuth Phishing Scam Targeting Developers
ID: 56ec09b2-922c-579f-9e58-ea293631ce74
STIX ID: report--56ec09b2-922c-579f-9e58-ea293631ce74
Feed Name: GBHackers
Attackers are exploiting GitHub issue notification emails to phish developers into authorizing malicious OAuth applications that request repository and Actions scopes; once authorized, the apps can clone private repos, inject backdoors, tamper workflows, and exfiltrate data. Because the emails come from GitHub infrastructure (passing SPF/DKIM) and attackers use tactics like TOCTOU edits and realistic naming, the lures are highly convincing; researchers observed campaigns impacting roughly 12,000 repositories. Organizations should treat OAuth approvals as high-risk, restrict which apps can be authorized, regularly review grants, and verify alerts directly on GitHub rather than clicking email links.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
