GitHub comments abused to spread password-stealing malware disguised as fixes
GitHub has been exploited to distribute the Lumma Stealer information-stealing malware, masquerading as fake fixes in project comments. The campaign was initially reported by a contributor to the teloxide rust library, who noticed five different comments on their GitHub issues that pretended to be fixes but were actually pushing malware. Upon further investigation, BleepingComputer found … Read more