A widespread phishing campaign is currently targeting GitHub repositories with fake security alerts, potentially compromising thousands of developer accounts.
Cybersecurity experts warn that these sophisticated attacks could grant hackers complete control over victims’ code repositories and personal information.
Security researcher Luc4m first identified the phishing operation that targeted nearly 12,000 GitHub repositories with fraudulent “Security Alert” issues.
The attackers have created GitHub accounts with deceptive names like “GitHub Notification” and proceed to open issues on well-known security repositories with the alarming title “Security Alert: Unusual Access Attempt”.
“We have detected a login attempt on your GitHub account that appears to be from a new location or device,” the fake alert reads.
The message consistently reports suspicious activity originating from Reykjavik, Iceland, associated with the IP address 53.253.117.8 This attack is particularly dangerous because of its exploitation of OAuth authentication protocols.
When unsuspecting developers click on the provided links to supposedly secure their accounts, they’re directed to authorize a malicious OAuth application named “gitsecurityapp”. This rogue application requests an extensive set of permissions, including:
Once granted, these permissions allow attackers to exfiltrate sensitive code, modify repositories, or even delete entire projects.
The campaign began on March 16, 2025, and remains active. The irregular number of targeted repositories suggests that GitHub is working to mitigate the attack.
While definitive attribution remains challenging, some security experts have suggested potential links to North Korean (DPRK) state-sponsored threat actors.
“Smells DPKR?” noted researcher Luc4m when discussing the possible origins of the attack.
GitHub users who may have interacted with these fake security alerts should take immediate action to protect their accounts and code:
As phishing techniques continue to advance, maintaining vigilance and implementing robust security practices like two-factor authentication becomes increasingly critical for developers protecting their code and credentials.
Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…