A large-scale phishing campaign is abusing GitHub Discussions to post fake Visual Studio Code security alerts that pressure developers into downloading malware from external links. The posts impersonate legitimate advisories with fabricated CVE identifiers, fake affected version ranges, and urgent language, while newly created or low-activity accounts mass-tag developers across unrelated repositories to expand reach. Because GitHub Discussions can trigger email notifications to watchers and participants, the operation gains additional credibility and visibility beyond the platform itself.
Analysis of the linked infrastructure showed a multi-stage redirection chain that used a Google share.google endpoint and the attacker-controlled domain drnatashachinn[.]com. The delivered JavaScript performed browser fingerprinting, cookie checks, obfuscation, and anti-analysis steps to distinguish real users from bots or security scanners before routing victims to later-stage malicious content, consistent with a traffic distribution system. Researchers said the campaign appears coordinated and automated, and urged developers to treat unsolicited GitHub security alerts with external download links as suspicious and verify VS Code updates only through official Microsoft channels.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Public reporting on the campaign highlighted that GitHub Discussions can amplify the lure through email notifications and advised developers not to trust unsolicited security alerts with external download links. The guidance recommended verifying Visual Studio Code updates only through official Microsoft channels.
Analysis of a linked payload revealed a multi-step redirection chain using a Google share.google endpoint and the attacker-controlled domain drnatashachinn[.]com. The JavaScript performed browser and environment fingerprinting, anti-analysis checks, and sent results back to the endpoint, indicating a traffic distribution system used to filter victims before later-stage malicious content.
A coordinated campaign used newly created or low-activity GitHub accounts to post hundreds to thousands of near-identical fake Visual Studio Code security alerts across repositories. The posts impersonated advisories with fabricated CVEs, fake version ranges, and mass-tagging of developers to pressure them into downloading software from external links.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcesocket.dev
Open sourceinfosec.pub
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.