{"id":11625,"date":"2026-03-26T10:03:44","date_gmt":"2026-03-26T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/03\/26\/fake-vs-code-security-alerts-on-github-used-to-push-malware-in-widespread-phishing-campaign\/"},"modified":"2026-03-26T10:03:44","modified_gmt":"2026-03-26T10:03:44","slug":"fake-vs-code-security-alerts-on-github-used-to-push-malware-in-widespread-phishing-campaign","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/03\/26\/fake-vs-code-security-alerts-on-github-used-to-push-malware-in-widespread-phishing-campaign\/","title":{"rendered":"Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign"},"content":{"rendered":"<p>    Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A large-scale phishing campaign is targeting software developers on GitHub, using fake Visual Studio Code security alerts posted in GitHub Discussions to trick users into downloading malicious software. <\/p>\n<p>The attacks are designed to look like legitimate security advisories, warning developers of critical vulnerabilities in VS Code and urging them to install a so-called \u201cpatched\u201d version through an external link.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c58f6a83-5fdb-46a2-bad7-9da3d812458e\/Fake-VS-Code-Security-Alerts-on-GitHub-Used-to-Push-Malware-in-Widespread-Phishing-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYEZMKCS4FE&amp;Signature=uPfPbBBoiMRkDCTZVVoWWSGD2gk%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIHOTcXWc4QdqVVAIkQvLPNOC66sGegaGgoohylpP5r7hAiA%2Fb69N1LNXnAUTKvtOeyU1JzOWuSExfoey9VKUOv9glir8BAi%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMsOZbbcu3MCKRzD4xKtAEMTGwRoL%2Fdb829XXY7Yek%2FWtdfRhY8evJctAruOQQjTPouBqmE962hSJkU8SCONGgWwRKo9PlROZHG%2BL6Ne81IcVkFf4A2%2B40ZpurxiCMAuaq6%2BNsIlsiahpsQpgaJewhfj7culmL7JXe2JsSSsTowAlTgdrDU8wAIp2H0q60DNgLm%2BzBjOc3ZhLChtjXTahy4tJE7PscE01I%2FBm1BQTFoiXwxiRKbPIweuIOnL4eytBbwT6mj0QHg3zuo3So6NKggk6O5bzA%2F1u1K8zS5ukaGkFJP1aHpp3vBJAsgAlIf0qWZ6BeTQo%2Fp6%2BzlPMi7dPN%2F9LkS%2FCaxqYQ6kCmfRqxuIvwuU9%2F4ipM6Bf%2FC6KfXacePJZOhJC%2FKklU4yeuYzr8XSDPv71o7HEIdijKFtfBtKU0iun8u4KB%2FVXssrlET4ANT5af%2FY5cNEqoQjhNZ%2B4a5v3uhE0S4Sx7JLtoMFYPm0whKlLqrMz63zvWkB7qduBQZrH6ica9o7MPcK15E1cDvgF7Uklowli8Ylj6lw%2FA2vT9C%2FefstsrkkWe2o4yI5sZIpMwPMd5W109719LP%2BiYoziuWKIyywO5pfL3VzfD3iPsTBfFWhus8y5ygRDf%2BFvXo8RnCreFGZWolSMUf%2FyxNz4EcJEefxwcbjR9SHEaTPjip7MiUo86hEnmJDrcirb3fzIF2wshsMJeE0uPTXhkFffx%2FoXZS7XC2Qw6nBhT%2FF1MhpcwXG5N0eP6rLYOm6V4mrJ3w6eNv5ycZoBmoYtrDtWnQaOzc%2BFs3IUNF%2BYiUTDXiZPOBjqZAfvNdMVSdHDQVDvMX4HzxbM0b%2B9LwhwYkDT42Z7KzOb3tczENQpKJ%2BIQ5gAhZSETNWTkosbUJtrok8rru0Ud8dOVW7%2BnsYKO50i9flG6t%2BU7HiGEfcu3iIoWSV61zC57U4dw3xrLWB0kIF%2FjfZPIscoaIW8gumTV7jSFCzUGTuJNE0fcqfCuoYi0oWMYGp%2FAazhdZJvCTROmug%3D%3D&amp;Expires=1774504643\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The campaign surfaced through thousands of near-identical posts flooding GitHub repositories within minutes of each other. <\/p>\n<p>Each post mimics an official security advisory, carrying alarming titles such as\u00a0\u201cVisual Studio Code \u2013 Severe Vulnerability \u2013 Immediate Update Required,\u201d\u00a0\u201cCritical Exploit \u2013 Urgent Action Needed,\u201d\u00a0and\u00a0\u201cSevere Threat \u2013 Update Immediately.\u201d\u00a0<\/p>\n<p>The posts often reference fabricated CVEs and fake version ranges to make the warnings appear credible. <\/p>\n<p>Since GitHub Discussions automatically trigger email notifications to repository participants and watchers, these fake alerts are also delivered directly to developers\u2019 inboxes, extending the campaign\u2019s reach far beyond the platform itself.\u00a0<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhjHTeUUqzROJSlo7jcwc7O_qjUyQ82IxJc18aselm7EJbpZwxz6bCiPmdzEInsGJzRuY4Q2tjAzIwfIf9VTmYthMeHWE9s2uQu_F7CCkPe_i_gu_DiObqwHzQTbCQciSGScC57vI4S5XqPttTirac53udUVdWqRkQ3rkOWPxNNPvafhosNngLLAIQZlQ4\/s16000\/Fake%2520GitHub%2520Discussion%2520Alert%2520%28Source%2520-%2520Socket.dev%29.webp?ssl=1\" alt=\"Fake GitHub Discussion Alert (Source - Socket.dev)\"><figcaption class=\"wp-element-caption\">Fake GitHub Discussion Alert (Source \u2013 Socket.dev)<\/figcaption><\/figure>\n<\/div>\n<p><a href=\"https:\/\/socket.dev\/blog\/widespread-github-campaign-uses-fake-vs-code-security-alerts-to-deliver-malware\" id=\"https:\/\/socket.dev\/blog\/widespread-github-campaign-uses-fake-vs-code-security-alerts-to-deliver-malware\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Socket.dev analysts identified the campaign<\/a> as a coordinated spam operation, noting that posts were being created by newly created or low-activity accounts, tagging large numbers of developers across unrelated repositories for maximum exposure. <\/p>\n<p>The researchers found that the campaign abuses GitHub\u2019s own notification system to make fake alerts appear both urgent and legitimate \u2014 a tactic that reduces a developer\u2019s natural skepticism when reading what looks like a trusted platform warning.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c58f6a83-5fdb-46a2-bad7-9da3d812458e\/Fake-VS-Code-Security-Alerts-on-GitHub-Used-to-Push-Malware-in-Widespread-Phishing-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYEZMKCS4FE&amp;Signature=uPfPbBBoiMRkDCTZVVoWWSGD2gk%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIHOTcXWc4QdqVVAIkQvLPNOC66sGegaGgoohylpP5r7hAiA%2Fb69N1LNXnAUTKvtOeyU1JzOWuSExfoey9VKUOv9glir8BAi%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMsOZbbcu3MCKRzD4xKtAEMTGwRoL%2Fdb829XXY7Yek%2FWtdfRhY8evJctAruOQQjTPouBqmE962hSJkU8SCONGgWwRKo9PlROZHG%2BL6Ne81IcVkFf4A2%2B40ZpurxiCMAuaq6%2BNsIlsiahpsQpgaJewhfj7culmL7JXe2JsSSsTowAlTgdrDU8wAIp2H0q60DNgLm%2BzBjOc3ZhLChtjXTahy4tJE7PscE01I%2FBm1BQTFoiXwxiRKbPIweuIOnL4eytBbwT6mj0QHg3zuo3So6NKggk6O5bzA%2F1u1K8zS5ukaGkFJP1aHpp3vBJAsgAlIf0qWZ6BeTQo%2Fp6%2BzlPMi7dPN%2F9LkS%2FCaxqYQ6kCmfRqxuIvwuU9%2F4ipM6Bf%2FC6KfXacePJZOhJC%2FKklU4yeuYzr8XSDPv71o7HEIdijKFtfBtKU0iun8u4KB%2FVXssrlET4ANT5af%2FY5cNEqoQjhNZ%2B4a5v3uhE0S4Sx7JLtoMFYPm0whKlLqrMz63zvWkB7qduBQZrH6ica9o7MPcK15E1cDvgF7Uklowli8Ylj6lw%2FA2vT9C%2FefstsrkkWe2o4yI5sZIpMwPMd5W109719LP%2BiYoziuWKIyywO5pfL3VzfD3iPsTBfFWhus8y5ygRDf%2BFvXo8RnCreFGZWolSMUf%2FyxNz4EcJEefxwcbjR9SHEaTPjip7MiUo86hEnmJDrcirb3fzIF2wshsMJeE0uPTXhkFffx%2FoXZS7XC2Qw6nBhT%2FF1MhpcwXG5N0eP6rLYOm6V4mrJ3w6eNv5ycZoBmoYtrDtWnQaOzc%2BFs3IUNF%2BYiUTDXiZPOBjqZAfvNdMVSdHDQVDvMX4HzxbM0b%2B9LwhwYkDT42Z7KzOb3tczENQpKJ%2BIQ5gAhZSETNWTkosbUJtrok8rru0Ud8dOVW7%2BnsYKO50i9flG6t%2BU7HiGEfcu3iIoWSV61zC57U4dw3xrLWB0kIF%2FjfZPIscoaIW8gumTV7jSFCzUGTuJNE0fcqfCuoYi0oWMYGp%2FAazhdZJvCTROmug%3D%3D&amp;Expires=1774504643\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Each fake Discussion includes a link to download the supposed updated version of VS Code, but these links point to file-sharing services rather than official distribution channels. <\/p>\n<p>Legitimate <a href=\"https:\/\/cybersecuritynews.com\/flaws-vs-code-marketplace-malicious-extensions\/\" id=\"67194\" target=\"_blank\" rel=\"noreferrer noopener\">VS Code<\/a> updates are never distributed this way, yet the urgency built into these posts is enough to push developers into clicking without hesitation. <\/p>\n<p>The attack blends smoothly into GitHub\u2019s collaborative environment, turning a developer\u2019s everyday workspace into a delivery channel for malware.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c58f6a83-5fdb-46a2-bad7-9da3d812458e\/Fake-VS-Code-Security-Alerts-on-GitHub-Used-to-Push-Malware-in-Widespread-Phishing-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYEZMKCS4FE&amp;Signature=uPfPbBBoiMRkDCTZVVoWWSGD2gk%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIHOTcXWc4QdqVVAIkQvLPNOC66sGegaGgoohylpP5r7hAiA%2Fb69N1LNXnAUTKvtOeyU1JzOWuSExfoey9VKUOv9glir8BAi%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMsOZbbcu3MCKRzD4xKtAEMTGwRoL%2Fdb829XXY7Yek%2FWtdfRhY8evJctAruOQQjTPouBqmE962hSJkU8SCONGgWwRKo9PlROZHG%2BL6Ne81IcVkFf4A2%2B40ZpurxiCMAuaq6%2BNsIlsiahpsQpgaJewhfj7culmL7JXe2JsSSsTowAlTgdrDU8wAIp2H0q60DNgLm%2BzBjOc3ZhLChtjXTahy4tJE7PscE01I%2FBm1BQTFoiXwxiRKbPIweuIOnL4eytBbwT6mj0QHg3zuo3So6NKggk6O5bzA%2F1u1K8zS5ukaGkFJP1aHpp3vBJAsgAlIf0qWZ6BeTQo%2Fp6%2BzlPMi7dPN%2F9LkS%2FCaxqYQ6kCmfRqxuIvwuU9%2F4ipM6Bf%2FC6KfXacePJZOhJC%2FKklU4yeuYzr8XSDPv71o7HEIdijKFtfBtKU0iun8u4KB%2FVXssrlET4ANT5af%2FY5cNEqoQjhNZ%2B4a5v3uhE0S4Sx7JLtoMFYPm0whKlLqrMz63zvWkB7qduBQZrH6ica9o7MPcK15E1cDvgF7Uklowli8Ylj6lw%2FA2vT9C%2FefstsrkkWe2o4yI5sZIpMwPMd5W109719LP%2BiYoziuWKIyywO5pfL3VzfD3iPsTBfFWhus8y5ygRDf%2BFvXo8RnCreFGZWolSMUf%2FyxNz4EcJEefxwcbjR9SHEaTPjip7MiUo86hEnmJDrcirb3fzIF2wshsMJeE0uPTXhkFffx%2FoXZS7XC2Qw6nBhT%2FF1MhpcwXG5N0eP6rLYOm6V4mrJ3w6eNv5ycZoBmoYtrDtWnQaOzc%2BFs3IUNF%2BYiUTDXiZPOBjqZAfvNdMVSdHDQVDvMX4HzxbM0b%2B9LwhwYkDT42Z7KzOb3tczENQpKJ%2BIQ5gAhZSETNWTkosbUJtrok8rru0Ud8dOVW7%2BnsYKO50i9flG6t%2BU7HiGEfcu3iIoWSV61zC57U4dw3xrLWB0kIF%2FjfZPIscoaIW8gumTV7jSFCzUGTuJNE0fcqfCuoYi0oWMYGp%2FAazhdZJvCTROmug%3D%3D&amp;Expires=1774504643\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>The scale of the campaign makes it particularly alarming. Hundreds to thousands of these posts appeared across GitHub search results in rapid succession, pointing to a heavily automated operation. <\/p>\n<p>The fact that developers are being targeted inside a platform they trust daily, rather than through traditional phishing emails, marks a notable shift in how attackers approach developer-focused threats.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c58f6a83-5fdb-46a2-bad7-9da3d812458e\/Fake-VS-Code-Security-Alerts-on-GitHub-Used-to-Push-Malware-in-Widespread-Phishing-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYEZMKCS4FE&amp;Signature=uPfPbBBoiMRkDCTZVVoWWSGD2gk%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIHOTcXWc4QdqVVAIkQvLPNOC66sGegaGgoohylpP5r7hAiA%2Fb69N1LNXnAUTKvtOeyU1JzOWuSExfoey9VKUOv9glir8BAi%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMsOZbbcu3MCKRzD4xKtAEMTGwRoL%2Fdb829XXY7Yek%2FWtdfRhY8evJctAruOQQjTPouBqmE962hSJkU8SCONGgWwRKo9PlROZHG%2BL6Ne81IcVkFf4A2%2B40ZpurxiCMAuaq6%2BNsIlsiahpsQpgaJewhfj7culmL7JXe2JsSSsTowAlTgdrDU8wAIp2H0q60DNgLm%2BzBjOc3ZhLChtjXTahy4tJE7PscE01I%2FBm1BQTFoiXwxiRKbPIweuIOnL4eytBbwT6mj0QHg3zuo3So6NKggk6O5bzA%2F1u1K8zS5ukaGkFJP1aHpp3vBJAsgAlIf0qWZ6BeTQo%2Fp6%2BzlPMi7dPN%2F9LkS%2FCaxqYQ6kCmfRqxuIvwuU9%2F4ipM6Bf%2FC6KfXacePJZOhJC%2FKklU4yeuYzr8XSDPv71o7HEIdijKFtfBtKU0iun8u4KB%2FVXssrlET4ANT5af%2FY5cNEqoQjhNZ%2B4a5v3uhE0S4Sx7JLtoMFYPm0whKlLqrMz63zvWkB7qduBQZrH6ica9o7MPcK15E1cDvgF7Uklowli8Ylj6lw%2FA2vT9C%2FefstsrkkWe2o4yI5sZIpMwPMd5W109719LP%2BiYoziuWKIyywO5pfL3VzfD3iPsTBfFWhus8y5ygRDf%2BFvXo8RnCreFGZWolSMUf%2FyxNz4EcJEefxwcbjR9SHEaTPjip7MiUo86hEnmJDrcirb3fzIF2wshsMJeE0uPTXhkFffx%2FoXZS7XC2Qw6nBhT%2FF1MhpcwXG5N0eP6rLYOm6V4mrJ3w6eNv5ycZoBmoYtrDtWnQaOzc%2BFs3IUNF%2BYiUTDXiZPOBjqZAfvNdMVSdHDQVDvMX4HzxbM0b%2B9LwhwYkDT42Z7KzOb3tczENQpKJ%2BIQ5gAhZSETNWTkosbUJtrok8rru0Ud8dOVW7%2BnsYKO50i9flG6t%2BU7HiGEfcu3iIoWSV61zC57U4dw3xrLWB0kIF%2FjfZPIscoaIW8gumTV7jSFCzUGTuJNE0fcqfCuoYi0oWMYGp%2FAazhdZJvCTROmug%3D%3D&amp;Expires=1774504643\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"multi-step-redirection-and-browser-fingerprinting\"><strong>Multi-Step Redirection and Browser Fingerprinting<\/strong><\/h2>\n<p>Socket.dev analysts traced one of the payloads linked in the fake Discussions and uncovered a carefully built multi-step redirection chain. Clicking the link first routes the victim through a Google share endpoint. <\/p>\n<p>From there, the path splits based on whether the user\u2019s browser carries a valid Google cookie. Users with a cookie are automatically sent via a 301 redirect to the attacker-controlled domain,\u00a0drnatashachinn[.]com, which functions as the campaign\u2019s command-and-control server. <\/p>\n<p>Users without a cookie are served a fingerprinting page directly from the Google endpoint, likely as a fallback to filter out bots and automated <a href=\"https:\/\/cybersecuritynews.com\/web-security-scanners\/\" id=\"11627\" target=\"_blank\" rel=\"noreferrer noopener\">security scanners<\/a>.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c58f6a83-5fdb-46a2-bad7-9da3d812458e\/Fake-VS-Code-Security-Alerts-on-GitHub-Used-to-Push-Malware-in-Widespread-Phishing-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYEZMKCS4FE&amp;Signature=uPfPbBBoiMRkDCTZVVoWWSGD2gk%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIHOTcXWc4QdqVVAIkQvLPNOC66sGegaGgoohylpP5r7hAiA%2Fb69N1LNXnAUTKvtOeyU1JzOWuSExfoey9VKUOv9glir8BAi%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMsOZbbcu3MCKRzD4xKtAEMTGwRoL%2Fdb829XXY7Yek%2FWtdfRhY8evJctAruOQQjTPouBqmE962hSJkU8SCONGgWwRKo9PlROZHG%2BL6Ne81IcVkFf4A2%2B40ZpurxiCMAuaq6%2BNsIlsiahpsQpgaJewhfj7culmL7JXe2JsSSsTowAlTgdrDU8wAIp2H0q60DNgLm%2BzBjOc3ZhLChtjXTahy4tJE7PscE01I%2FBm1BQTFoiXwxiRKbPIweuIOnL4eytBbwT6mj0QHg3zuo3So6NKggk6O5bzA%2F1u1K8zS5ukaGkFJP1aHpp3vBJAsgAlIf0qWZ6BeTQo%2Fp6%2BzlPMi7dPN%2F9LkS%2FCaxqYQ6kCmfRqxuIvwuU9%2F4ipM6Bf%2FC6KfXacePJZOhJC%2FKklU4yeuYzr8XSDPv71o7HEIdijKFtfBtKU0iun8u4KB%2FVXssrlET4ANT5af%2FY5cNEqoQjhNZ%2B4a5v3uhE0S4Sx7JLtoMFYPm0whKlLqrMz63zvWkB7qduBQZrH6ica9o7MPcK15E1cDvgF7Uklowli8Ylj6lw%2FA2vT9C%2FefstsrkkWe2o4yI5sZIpMwPMd5W109719LP%2BiYoziuWKIyywO5pfL3VzfD3iPsTBfFWhus8y5ygRDf%2BFvXo8RnCreFGZWolSMUf%2FyxNz4EcJEefxwcbjR9SHEaTPjip7MiUo86hEnmJDrcirb3fzIF2wshsMJeE0uPTXhkFffx%2FoXZS7XC2Qw6nBhT%2FF1MhpcwXG5N0eP6rLYOm6V4mrJ3w6eNv5ycZoBmoYtrDtWnQaOzc%2BFs3IUNF%2BYiUTDXiZPOBjqZAfvNdMVSdHDQVDvMX4HzxbM0b%2B9LwhwYkDT42Z7KzOb3tczENQpKJ%2BIQ5gAhZSETNWTkosbUJtrok8rru0Ud8dOVW7%2BnsYKO50i9flG6t%2BU7HiGEfcu3iIoWSV61zC57U4dw3xrLWB0kIF%2FjfZPIscoaIW8gumTV7jSFCzUGTuJNE0fcqfCuoYi0oWMYGp%2FAazhdZJvCTROmug%3D%3D&amp;Expires=1774504643\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Once a real user lands on the attacker\u2019s infrastructure, an obfuscated JavaScript payload executes immediately. <\/p>\n<p>The script gathers browser fingerprint data, including timezone, locale, platform, user agent, and automation signals like\u00a0<code>navigator.webdriver<\/code>, used to identify whether the visitor is a real person or a bot. <\/p>\n<p>A hidden iframe further cross-checks the user agent to detect spoofed environments. All collected data is then silently submitted to the attacker\u2019s endpoint via an automatic POST request, requiring no interaction from the victim. <\/p>\n<p>This profiling stage acts as a filtering layer, sorting real users from scanners before routing confirmed targets to a follow-on payload, such as a phishing page or exploit kit.<a href=\"https:\/\/ppl-ai-file-upload.s3.amazonaws.com\/web\/direct-files\/attachments\/11146061\/c58f6a83-5fdb-46a2-bad7-9da3d812458e\/Fake-VS-Code-Security-Alerts-on-GitHub-Used-to-Push-Malware-in-Widespread-Phishing-Campaign.pdf?AWSAccessKeyId=ASIA2F3EMEYEZMKCS4FE&amp;Signature=uPfPbBBoiMRkDCTZVVoWWSGD2gk%3D&amp;x-amz-security-token=IQoJb3JpZ2luX2VjEPb%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJGMEQCIHOTcXWc4QdqVVAIkQvLPNOC66sGegaGgoohylpP5r7hAiA%2Fb69N1LNXnAUTKvtOeyU1JzOWuSExfoey9VKUOv9glir8BAi%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F%2F8BEAEaDDY5OTc1MzMwOTcwNSIMsOZbbcu3MCKRzD4xKtAEMTGwRoL%2Fdb829XXY7Yek%2FWtdfRhY8evJctAruOQQjTPouBqmE962hSJkU8SCONGgWwRKo9PlROZHG%2BL6Ne81IcVkFf4A2%2B40ZpurxiCMAuaq6%2BNsIlsiahpsQpgaJewhfj7culmL7JXe2JsSSsTowAlTgdrDU8wAIp2H0q60DNgLm%2BzBjOc3ZhLChtjXTahy4tJE7PscE01I%2FBm1BQTFoiXwxiRKbPIweuIOnL4eytBbwT6mj0QHg3zuo3So6NKggk6O5bzA%2F1u1K8zS5ukaGkFJP1aHpp3vBJAsgAlIf0qWZ6BeTQo%2Fp6%2BzlPMi7dPN%2F9LkS%2FCaxqYQ6kCmfRqxuIvwuU9%2F4ipM6Bf%2FC6KfXacePJZOhJC%2FKklU4yeuYzr8XSDPv71o7HEIdijKFtfBtKU0iun8u4KB%2FVXssrlET4ANT5af%2FY5cNEqoQjhNZ%2B4a5v3uhE0S4Sx7JLtoMFYPm0whKlLqrMz63zvWkB7qduBQZrH6ica9o7MPcK15E1cDvgF7Uklowli8Ylj6lw%2FA2vT9C%2FefstsrkkWe2o4yI5sZIpMwPMd5W109719LP%2BiYoziuWKIyywO5pfL3VzfD3iPsTBfFWhus8y5ygRDf%2BFvXo8RnCreFGZWolSMUf%2FyxNz4EcJEefxwcbjR9SHEaTPjip7MiUo86hEnmJDrcirb3fzIF2wshsMJeE0uPTXhkFffx%2FoXZS7XC2Qw6nBhT%2FF1MhpcwXG5N0eP6rLYOm6V4mrJ3w6eNv5ycZoBmoYtrDtWnQaOzc%2BFs3IUNF%2BYiUTDXiZPOBjqZAfvNdMVSdHDQVDvMX4HzxbM0b%2B9LwhwYkDT42Z7KzOb3tczENQpKJ%2BIQ5gAhZSETNWTkosbUJtrok8rru0Ud8dOVW7%2BnsYKO50i9flG6t%2BU7HiGEfcu3iIoWSV61zC57U4dw3xrLWB0kIF%2FjfZPIscoaIW8gumTV7jSFCzUGTuJNE0fcqfCuoYi0oWMYGp%2FAazhdZJvCTROmug%3D%3D&amp;Expires=1774504643\" target=\"_blank\" rel=\"noreferrer noopener\"><\/a><\/p>\n<p>Developers should treat all unsolicited <a href=\"https:\/\/cybersecuritynews.com\/fake-github-security-alerts-let-hackers-hijack\/\" id=\"96473\" target=\"_blank\" rel=\"noreferrer noopener\">security alerts<\/a> in GitHub Discussions with caution, especially when posts include external download links, unverifiable CVE references, urgent install instructions, mass tagging of unrelated users, or content from recently created accounts. <\/p>\n<p>Security updates for VS Code should always be verified through official Microsoft channels only, and any suspicious Discussion should be reported directly to GitHub for review.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 91%,rgb(169,184,195) 100%)\"><strong>Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a>\u00a0to Get More Instant Updates<\/strong>,\u00a0<strong>Set CSN as a Preferred Source in\u00a0<a href=\"https:\/\/www.google.com\/preferences\/source?q=cybersecuritynews.com\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google<\/a>.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/fake-vs-code-security-alerts-on-github\/\">Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/fake-vs-code-security-alerts-on-github\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Fake VS Code Security Alerts on GitHub Used to Push Malware in Widespread Phishing Campaign A large-scale phishing campaign is targeting software developers on GitHub, using fake Visual Studio Code security alerts posted in GitHub Discussions to trick users into downloading malicious software. The attacks are designed to look like legitimate security advisories, warning developers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-11625","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11625"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=11625"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/11625\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=11625"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=11625"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=11625"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}