Fake VS Code alerts on GitHub spread malware to developers
ID: cdb8de67-72fc-55de-852a-8a17c1090369
STIX ID: report--cdb8de67-72fc-55de-852a-8a17c1090369
Feed Name: Bleeping Computer
Security researchers report a coordinated, large-scale campaign that posts fake Visual Studio Code security alerts in GitHub Discussions to lure developers into downloading purportedly patched extensions from external links (e.g., Google Drive). Clicking the links leads to a redirection chain to drnatashachinn.com where a JavaScript reconnaissance script collects environment and automation indicators to profile victims via a traffic distribution system, with the operator delivering a second-stage payload only to validated targets; the campaign employs impersonation, mass tagging, and automated low-reputation accounts across thousands of repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
