HomeSecurityDeepSource: Restores logins after employee falls victim to phishing

DeepSource: Restores logins after employee falls victim to phishing

GitHub notified DeepSource earlier this month of the detection of malicious activity related to the GitHub app after one of its employees fell victim to the Sawfish phishing campaign.

DeepSource provides developers with automated static code analysis tools for GitHub, GitLab, and Bitbucket repositories that help identify and resolve issues during code review. According to its website, the startup's client list includes Intel, NASA, Slack, and Uber.

DeepSource

Sawfish operators have been targeting GitHub users since April 2020 as part of a series of spearphishing specifically designed to steal their credentials using phishing pages that mimic the GitHub login page.

DeepSource employee credentials stolen by Sawfish

According to an alert received by DeepSource on the morning of July 11, DeepSource users were making numerous requests from unusual IP addresses that sparked the attention of the GitHub Security team who began monitoring the activity as potentially malicious.

While GitHub was unable to pinpoint the source of the breach at the time, within two hours, DeepSource “reversed” all user tokens, client secrets, and private keys, as well as “all employee credentials and keys that had access to production systems.”

Five days later, on July 16, the GitHub security team informed DeepSource that one of its employees had been victimized and had his GitHub application credentials stolen in the Sawfish phishing campaign.

“Unfortunately, GitHub’s privacy policy prevents them from sharing the list of affected users with us, so we are disclosing this issue publicly while we wait for GitHub to complete its investigation,” DeepSource explained. “We understand that GitHub will notify directly affected users in accordance with its policies.”

“You should visit https://support.github.com/contact?subject=GH-0000502-3963-3+Log+Request&tags=GH-0000502-3963-3 and request the logs regarding repository downloads and other account activities to find any suspicious activity.”

DeepSource notified all users via email on the afternoon of July 20th about this security incident and plans to launch a bug bounty to ask security to investigate its systems for security vulnerabilities.

The Sawfish phishing campaign

In April, GitHub's Security Incident Response Team (SIRT) notified all customers of an ongoing phishing campaign now known as Sawfish, which is actively collecting victims' GitHub credentials and 2FA (if they use a TOTP password in the mobile app).

As detailed on GitHub, accounts protected using hardware security keys were not vulnerable to the Sawfish attack.

GitHub said that the attackers were using stolen credentials to take over their victims' accounts and that they were also rapidly downloading the contents of private repositories, including those belonging to organization and other collaborators.

"If an attacker successfully steals a GitHub user's credentials, they may be able to quickly generate personal access tokens or authorize OAuth applications on the account to maintain access in the event the user changes their password," GitHub added.

A year ago, phishers were also using GitHub's platform to host a phishing kit, abusing the service's free repositories to deliver malware via github.io pages.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS