Cyber Security News

Hackers Leverage GitHub Notifications to Mimic as Y Combinator to Steal Funds from Wallets

Cybercriminals have orchestrated a sophisticated phishing campaign exploiting GitHub’s notification system to impersonate the prestigious startup accelerator Y Combinator, targeting developers’ cryptocurrency wallets through fake funding opportunity notifications.

The attack leverages GitHub’s issue tracking system to mass-distribute phishing notifications, bypassing traditional email security filters by using the platform’s legitimate notification infrastructure. 

Threat actors created multiple GitHub accounts with names closely resembling Y Combinator, including ycombinato, ycommbbinator, and ycoommbinator, along with a malicious GitHub application called ycombinatornotify.

Y Combinator Phishing Scam

The attackers demonstrated a sophisticated understanding of GitHub’s API limitations and notification mechanisms. 

Each malicious repository generated approximately 500 issues before hitting GitHub’s rate-limiting thresholds, with each issue containing phishing content and tagging numerous random GitHub usernames to maximize notification distribution. 

The notifications appeared authentic since they originated from GitHub’s official notification system, making them difficult for users to identify as fraudulent immediately.

The phishing messages claimed recipients had been “selected for funding” and required wallet verification or authorization deposits to access supposed Y Combinator investment opportunities. 

This social engineering technique targets explicitly the developer community’s familiarity with Y Combinator’s legitimate application process, exploiting the prestige and desirability associated with acceptance into the accelerator program.

The operation employed typosquatting techniques, registering the domain y-comblnator.com (substituting an “L” for the “I” in “combinator”) to create a convincing replica of Y Combinator’s legitimate website. 

This domain hosted fake application pages designed to harvest cryptocurrency wallet credentials and private keys from unsuspecting victims.

GitHub’s security team responded by suspending the malicious accounts and repositories, but the attack’s distributed nature across multiple accounts created persistence challenges. 

Affected users reported staying notification badges that required manual API calls to clear, using commands like curl -X PATCH with authentication tokens to mark phantom notifications as read. 

The incident highlights the vulnerability of collaborative development platforms to abuse, where legitimate notification systems can be weaponized for large-scale phishing campaigns targeting the cryptocurrency assets of technical professionals who represent high-value targets due to their likely digital asset holdings.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Florence Nightingale

Florence Nightingale is a senior security and privacy reporter, covering data breaches, cybercrime, malware, and data leaks from cyber space daily.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

16 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago