A large-scale phishing campaign is abusing GitHub Discussions to post fake Visual Studio Code security alerts that pressure developers into downloading malware from external links. The posts impersonate legitimate advisories with fabricated CVE identifiers, fake affected version ranges, and urgent language, while newly created or low-activity accounts mass-tag developers across unrelated repositories to expand reach. Because GitHub Discussions can trigger email notifications to watchers and participants, the operation gains additional credibility and visibility beyond the platform itself.
Analysis of the linked infrastructure showed a multi-stage redirection chain that used a Google share.google endpoint and the attacker-controlled domain drnatashachinn[.]com. The delivered JavaScript performed browser fingerprinting, cookie checks, obfuscation, and anti-analysis steps to distinguish real users from bots or security scanners before routing victims to later-stage malicious content, consistent with a traffic distribution system. Researchers said the campaign appears coordinated and automated, and urged developers to treat unsolicited GitHub security alerts with external download links as suspicious and verify VS Code updates only through official Microsoft channels.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting on the campaign highlighted that GitHub Discussions can amplify the lure through email notifications and advised developers not to trust unsolicited security alerts with external download links. The guidance recommended verifying Visual Studio Code updates only through official Microsoft channels.
Analysis of a linked payload revealed a multi-step redirection chain using a Google share.google endpoint and the attacker-controlled domain drnatashachinn[.]com. The JavaScript performed browser and environment fingerprinting, anti-analysis checks, and sent results back to the endpoint, indicating a traffic distribution system used to filter victims before later-stage malicious content.
A coordinated campaign used newly created or low-activity GitHub accounts to post hundreds to thousands of near-identical fake Visual Studio Code security alerts across repositories. The posts impersonated advisories with fabricated CVEs, fake version ranges, and mass-tagging of developers to pressure them into downloading software from external links.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesocket.dev
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.