logo

Gitloker attacks abuse GitHub notifications to push malicious oAuth apps

ID: d39f5817-f42b-53b6-a8d6-c632011e0cb9

STIX ID: report--d39f5817-f42b-53b6-a8d6-c632011e0cb9

Feed Name: Bleeping Computer

Threat Score
68/100

Date Published: 2024-06-10

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Threat actors are running an ongoing GitHub-targeted extortion campaign that uses compromised accounts and spam mentions to deliver phishing emails impersonating GitHub; victims are redirected to malicious domains that request OAuth authorization granting broad repository and data access. Attackers use obtained access to wipe and rename repositories, leave ransom notes directing victims to Telegram, and claim data theft, causing account disablement and loss of repository data for dozens of developers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.