TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Is anyone else getting spammed via GitHub recently?

105 pointsby aehardingover 2 years ago
Earlier today, a number of people I know have been spammed via GitHub issues and discussions, using @-mentions. Push notifications and emails sent. Very annoying because the report process for spamming on GitHub is not that quick.

27 comments

TranquilMarmotover 2 years ago
Yes! I was disappointed at how many steps reporting the malicious user took. I think it was like 10 clicks to finally submit the report, almost like they wanted to make it difficult.
评论 #34173419 未加载
评论 #34171401 未加载
ssss11over 2 years ago
Oh, I thought the hot chicks were really for me…….. damn you github (and fb, email, TikTok, Twitter and so on….)
blahblah1234567over 2 years ago
Yep.<p>The content of the email was:<p>&quot; Message me when you are free <a href="https:&#x2F;&#x2F;to.sv&#x2F;SomeUUID" rel="nofollow">https:&#x2F;&#x2F;to.sv&#x2F;SomeUUID</a><p>&lt;list of about 40 users w&#x2F; @ sign preceding their github handle&gt;<p>Hey All my photos and videos here <a href="https:&#x2F;&#x2F;to.sv&#x2F;SameUUIDAsAbove" rel="nofollow">https:&#x2F;&#x2F;to.sv&#x2F;SameUUIDAsAbove</a> &quot;<p>Very suspicious. I searched the URL on a malicious link lookup site and found &quot;7 security vendors flagged this URL as malicious&quot;
评论 #34170196 未加载
评论 #34170954 未加载
rpigabover 2 years ago
Yes, on a random discussion about editing the README I never interacted with, on a repo I like (BurntSushi&#x27;s ripgrep) but do not remember interacting with, no star, no follow, no fork or anything else from me (I should star it and interact though, it&#x27;s awesome).<p>A lady mentionning something getting wet, many mentions including me and the same type of link others mentionned.
评论 #34171793 未加载
metadatover 2 years ago
Yes I also got one today.<p>Couldn&#x27;t find any &quot;report spam&quot; or &quot;report post&quot; link.
评论 #34204020 未加载
codegeekover 2 years ago
Yes got it an hour or 2 ago. Totally unrelated and no idea how I got tagged.
lfconsultover 2 years ago
Yes, just happened this morning... First, I received a GitHub notification without tag (I even didn&#x27;t know how is it possible) then I was tagged in a comment to a README &quot;I’m completely nak*d Wanna see the photo&quot; plus a link (obviously)...<p>Edit: It&#x27;s in the &quot;Discussions&quot; GitHub tab.<p>Edit: Got a GH response:<p>&quot;Our review of the account(s) and&#x2F;or content named in your report has concluded. We have determined that one or more violations of GitHub’s Terms of Service have occurred and have taken appropriate action in response.&quot;
david_allisonover 2 years ago
Yes, I contributed a small documentation fix to a service. I&#x27;m now assumed to be a maintainer and users tag me in issues whenever the service goes down.<p>These issues have hundreds of replies, and GitHub has UX problems on large issues: comments you&#x27;re tagged in aren&#x27;t immediately visible, which discourages reporting (it may take ~2&#x2F;3 minutes to expand a conversation to find and report it).<p>It discourages future contributions to repos I don&#x27;t maintain.
signaruover 2 years ago
Got one, the links and repo look legit (on first glance at least). But I have absolutely no idea why I am cc&#x27;ed on it.<p>I&#x27;m replacing the specifics with words in &quot;&lt;&gt;&quot;, but here&#x27;s the title of my mail from notifications@github.com:<p>Re: [&lt;user&gt;&#x2F;&lt;repo&gt;] &lt;what looks like an issue title&gt; (Discussion &lt;#number&gt;)
flawnover 2 years ago
<a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;github&#x2F;comments&#x2F;zxq399&#x2F;spammers_also_now_leveraging_github&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;github&#x2F;comments&#x2F;zxq399&#x2F;spammers_als...</a>
mekenover 2 years ago
Yes I got my first ever GitHub spam today :(
bosky101over 2 years ago
I did start seeing unrelated repos under topics&#x2F;x
elforce002over 2 years ago
Yes. Yesterday. It was right after I commented on an issue. This is the first time I get that. The interesting thing is that the spam had users that didn&#x27;t comment on the actual issue.
kobarokoover 2 years ago
Is there some setting in GitHub to prevent this messages from coming?
GabeIskoover 2 years ago
Happened to me a few days ago. Added to a korean github, a lot of repositories that are called &quot;pre-onboarding&quot; or something. Anyone know what is going on?
trashfaceover 2 years ago
Same for me. Onlyfans and github have merged I guess.
version_fiveover 2 years ago
What kind of repos is this happening for? Like is it targeting personal projects, contributions to bigger open source projects, or something else?
评论 #34169181 未加载
评论 #34168626 未加载
LinuxBenderover 2 years ago
Yes. I nuked my GitHub email canary. The spam comes across as a mail-list thread with a thread ID.
sambhuover 2 years ago
Yes, with random GitHub users mentioned and link to some adult malicious site
4silvertoothover 2 years ago
Yes, I got it just now, I haven&#x27;t stared that repo, or have any mentions.
nop_slideover 2 years ago
Yep I literally just got one 10 mins ago and saw this thread.
cjkover 2 years ago
Yep. First time I’ve seen anything like that on GitHub.
schemescapeover 2 years ago
Yes, just got one.<p>Edit: and another…
eurticketover 2 years ago
Yes
martin-adamsover 2 years ago
Yes, happened just now
jucaguirrearover 2 years ago
yes
masukomiover 2 years ago
yup.