logo

GitHub Repos Targeted in Cyber-Extortion Attacks

ID: 34a3f3fc-bf72-5284-9e04-866f0e42ebca

STIX ID: report--34a3f3fc-bf72-5284-9e04-866f0e42ebca

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2024-06-07

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

An extortion campaign attributed to an actor calling itself "Gitloker" is exploiting GitHub's commenting/notification features to send phishing emails appearing from [email protected] and to trick victims into authorizing OAuth apps, resulting in repository deletion, data theft, and ransom demands. Multiple users have reported compromises since at least February 2024; observed infrastructure includes the domains githubcareers.online and githubtalentcommunity.online, and GitHub advises reviewing sessions, personal access tokens, OAuth app authorizations, passwords, and two-factor recovery codes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.