Malicious actors are targeting GitHub repositories with Gitloker attacks, deleting their content, and asking victims to contact them via Telegram for more information.
See also: GitHub warns of SAML auth bypass flaw

These attacks are part of what appears to be an ongoing campaign that was first spotted on Wednesday by Germán Fernández, a security researcher at Chilean cybersecurity firm CronUp.
The threat actor behind this campaign – who runs Gitloker on Telegram and poses as a cyber incident analyst – is likely hacking targets’ GitHub accounts using stolen credentials.
They then claim to steal victims' data, creating a backup that could help restore deleted data. They then rename the repository and add a single README.me, instructing victims to contact Telegram.
“I hope this message finds you well. This is an urgent notification to inform you that your data has been compromised and we have secured a backup,” the ransom notes state.
See also: GitHub comments are being abused to promote malware
Following previous attacks on GitHub users, the company advised users to change their passwords to protect their accounts from Gitloker attacks. This should protect against malicious actions such as adding new SSH keys, authorizing new applications, or modifying team members.

To prevent attackers from compromising your GitHub account and detect any suspicious activity, you should also:
- Enable two-factor authentication.
- Add a password for secure, passwordless login.
- Review and revoke unauthorized access to SSH keys, deployment keys, and authorized integrations.
- Verify all email addresses associated with your account.
- Check the account security logs to monitor changes in the storage space.
- Manage webhooks in repositories .
- Check and revoke any new development keys.
- Regularly check recent commits and collaborators for each repository.
See also: Malicious Visual Studio projects on GitHub push Keyzetsu
GitHub, which has been the target of Gitloker attacks, is an online platform that uses Git, a version control system, to facilitate collaborative software development. It hosts code repositories that developers can clone, modify, and merge, enabling efficient project management and seamless collaboration. In addition to storing code, GitHub offers issue tracking, project wikis, and continuous integration services, making it a complete tool for developers. The platform also supports extensive community engagement, allowing developers to contribute to open source projects, share knowledge, and showcase their work through detailed documentation and README.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
