logo

Hackers Create Legit Phishing Links With Ghost GitHub, GitLab Comments

ID: 613c8866-10ca-5a88-8967-785ad68ac293

STIX ID: report--613c8866-10ca-5a88-8967-785ad68ac293

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-04-23

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

Attackers are abusing GitHub/GitLab comment file-upload behavior to create persistent, repo-branded URLs that host malware (even when comments are deleted or never published). This method has been used to distribute the RedLine Stealer, enabling highly believable phishing links tied to legitimate open-source repositories while leaving repository owners with little recourse.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.