logo

GitHub notifications abused to impersonate Y Combinator for crypto theft

ID: 64e6947b-4d7c-5727-b2c6-28940478d987

STIX ID: report--64e6947b-4d7c-5727-b2c6-28940478d987

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2025-09-24

Date Updated: 2026-07-17

Author: Bill Toulas

...
...

A large phishing campaign abused GitHub issue notifications to impersonate Y Combinator and deliver fake W2026 application invitations that linked to a typo-squatted site running obfuscated JavaScript. The site prompted EIP-712/Ethereum Attestation-style wallet signatures that actually authorized drain transactions; repositories creating the notifications were removed after reports, but the extent of losses is unclear.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.