TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GitHub Phishing Campaign making use of OAuth and render.com hosted site

8 pointsby PaoloBarbolini2 months ago
A phishing campaign has been ongoing in the last 4 hours, opening more than 11.5k issues containing the wording &quot;We have detected a login attempt on your GitHub account that appears to be from a new location or device.&quot; and links to a render.com hosted site.<p>Do not click any of the links!<p>Every once in a while this seems to reoccur, and I realize how slow GitHub is at deleting the spam issues or comments. Why doesn&#x27;t GitHub fix this?

4 comments

scottbez12 months ago
I recognize that anti-abuse is a neverending cat and mouse game, and hindsight is 20&#x2F;20, but it seems like malicious activity like this should be easily detected - how often does a legitimate account suddenly post 300 issues across many different repos?<p>Part of the challenge may be the moderation effort with false positives if you make detection more sensitive, but it seems like some investment in a pending&#x2F;flagged activity section with approval delegated to repo owners could work well?<p>In a past life, one of the more effective anti-abuse mechanisms was intentionally introducing latency between attempt and confirmation, on the order of a week. If every time you try to see if you&#x27;ve evaded detection takes a week to confirm, you can&#x27;t iterate on abuse nearly as quickly and are more likely to give up and move onto other targets. Obviously the amount of acceptable latency you can introduce will depend on the system&#x2F;product...
评论 #43380136 未加载
PaoloBarbolini2 months ago
Link to search results: <a href="https:&#x2F;&#x2F;github.com&#x2F;search?q=%22We+have+detected+a+login+attempt+on+your+GitHub+account+that+appears+to+be+from+a+new+location+or+device.%22&amp;type=issues&amp;s=created&amp;o=desc" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;search?q=%22We+have+detected+a+login+atte...</a>
anurag2 months ago
I work at Render. We&#x27;ve removed the phishing website from the platform.
评论 #43380015 未加载
pepoluan2 months ago
11.5k in 4h and GitHub does nothing??<p>That&#x27;s truly a HUGE red flag there.