logo

Clever 'GitHub Scanner' campaign abusing repos to push malware

ID: e3589430-a1ec-54cf-a831-519a5d80d616

STIX ID: report--e3589430-a1ec-54cf-a831-519a5d80d616

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2024-09-19

Date Updated: 2026-04-20

Author: Ax Sharma

...
...

A phishing campaign is abusing GitHub Issues to trigger legitimate GitHub notification emails that lure repository contributors to a fake domain (github-scanner[.]com). The site uses a bogus captcha and JavaScript clipboard tricks to get victims to paste a PowerShell command into Windows Run, which downloads and executes a trojan (l6E.exe / SysSetup.exe) identified as the Lumma Stealer information-stealing malware; the malware can harvest browser credentials, cookies, history, cryptocurrency wallets, and files. Multiple suspicious callback domains and a VirusTotal sample are noted, and users are advised to avoid links in such notifications and report the issues to GitHub.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.