Security Alert: Phishing Attempt on My GitHub Repository #154057
Replies: 3 comments 4 replies
-
|
Thanks for sharing, @yours7himanshu - seeing similar activity in my organization. The GitHub user was different but the text of the issue is identical. The links in the issue point to the onrender.com domain. |
Beta Was this translation helpful? Give feedback.
-
|
Hi @yours7himanshu, Thanks for sharing this, this user has also received the same scam attempt #154066. I recommend reporting the user(s) via GitHub's abuse reporting tools. |
Beta Was this translation helpful? Give feedback.
-
|
i have faced the same issue a few hours ago today. I have restored my repositories and changes my password but i am still worried, if this is going to be a serious issue. |
Beta Was this translation helpful? Give feedback.


Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Show & Tell
Body
Hello GitHub Community,
I wanted to share a recent incident that occurred on one of my repositories to raise awareness and help others avoid falling victim to similar scams.
What Happened:
An individual created an issue on my GitHub repository. The issue contained a message that implied someone had signed in to my GitHub account from an unusual device and location. The message further urged me to click on a link to verify the activity and change my password if it wasn't me.
The Deceptive Tactic:
The link provided in the issue appeared legitimate at first glance. However, upon closer inspection, the link was designed to request full access to my GitHub account. This included permissions to:
In essence, the link aimed to compromise my entire GitHub account by gaining unauthorized access to all my repositories and settings.
Recommendations for the Community:
By sharing this experience, I hope to prevent others from falling victim to similar phishing attempts. Stay vigilant and keep your code safe!
Thank you,


Himanshu Dinkar
Beta Was this translation helpful? Give feedback.
All reactions