A sophisticated campaign is exploiting GitHub repositories to distribute the Lumma Stealer malware. It specifically targets users who visit open-source projects or subscribe to notifications for them. Attackers create a fake GitHub user and open a new “issue” on an open-source repository, falsely claiming a security vulnerability in the project. They direct users to a malicious domain, “github-scanner[.]com,” under the guise of a legitimate GitHub security alert. Users receive email notifications from GitHub’s official address, making the campaign appear authentic. Upon visiting the counterfeit site, users are tricked into executing a malicious script by passing a fake captcha, leading to the installation of the Lumma Stealer malware. The malware primarily steals credentials, authentication cookies, and browsing history from web browsers, as well as cryptocurrency wallets and files containing sensitive information. This campaign exploits the trust placed in GitHub's notification system, with the malicious “issues” triggering email alerts from legitimate GitHub servers to users subscribed to the affected repositories. Once installed, the malware tries to connect to several suspicious domains to perform its data-stealing operations. The misuse of GitHub's "Issues" feature by threat actors highlights the potential for abuse on popular platforms. This incident shows a creative social engineering tactic, blending phishing with code execution, to compromise developers and steal sensitive data.
A recently disclosed supply chain vulnerability in Anthropic’s Claude Code GitHub Actions integration exposed numerous repositories to potential compromise through a single malic...
A critical security vulnerability affecting KMW CCTV cameras has been disclosed under CVE-2026-5386. The flaw allows attackers to bypass authentication controls and change device c...
A critical vulnerability, tracked as CVE-2026-4387, has been disclosed in StrongDM, exposing organizations to authentication token theft and session hijacking. Discovered by Specte...