A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake “Security Alert” reports, misleading developers into authorizing a malicious OAuth application, which gives attackers full control over their accounts and code.
See also: GitVenom: Fake GitHub repositories distribute malware

All of the phishing issues related to GitHub include the same text, warning users that unusual activity was observed on their account from Reykjavik, Iceland, and the IP address 53.253.117.8.
Cybersecurity researcher Luc4m was the first to spot the fake Security Alerts, which warned users that their account had been compromised and advised them to update their password, check and manage their active sessions, and enable two-factor authentication to secure their accounts.
However, all links to these suggested actions lead to a GitHub authorization page for an OAuth application named “gitsecurityapp,” which requests multiple dangerous permissions (scopes) and would allow an attacker full access to a user’s account and repositories.
The requested permissions and the access they provide are listed below:
- repo: Provides full access to public and private repositories
- user: Ability to read and write to the user profile
- read:org: Access to organization membership, organization projects, and team participation
- read: discussion, write:discussion: Read and write access to discussions
- gist: Access to GitHub concepts
- delete_repo: Permission to delete repositories
- workflows, workflow, write:workflow, read:workflow, update:workflow: Control GitHub Actions workflows
See also: GitHub: Fake PoC exploit for infostealer vulnerability is distributed

If a GitHub user logs in and authorizes the malicious OAuth application, an access which will be sent back to the application's callback address, which in this campaign has various web pages hosted on onrender.com (Render).
The phishing campaign began Sunday morning at 6:52 a.m. ET, with nearly 12,000 repositories targeted. However, that number is fluctuating, suggesting that GitHub may be responding to the attack.
If you were affected by this Security Alert attack and accidentally authorized the malicious OAuth application, you should immediately revoke its access by going to GitHub Settings and then Applications .
From the Apps screen, revoke access to any GitHub apps or OAuth apps that are unknown or suspicious. In this campaign, you should look for apps named similar to “gitsecurityapp“. Next, you should look for new or unexpected GitHub actions (Workflows) and if any private tokens were created. Finally, change your credentials and authorization tokens.
See also: Over 3.1 million fake stars on GitHub projects
Phishing campaigns are cyberattacks that aim to trick victims into revealing personal data, such as passwords, credit card numbers, or other sensitive information. Phishing attacks carried out through fake emails, messages, or websites that appear to come from trusted sources, such as banks, companies, or other organizations. The goal of these campaigns is to convince the victim to click on a link or open an attachment that contains malware or to reveal sensitive information, which could be used for fraud or identity theft.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
