<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🦋 🚨 We’re seeing a widespread GitHub campaign using fake VS Code alerts + Google redirects to route developers to attacker infrastructure.]]></title><description><![CDATA[<p><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f98b.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--butterfly"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="🦋"
      alt="🦋"
    /> <img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f6a8.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--rotating_light"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="🚨"
      alt="🚨"
    /> We’re seeing a widespread GitHub campaign using fake VS Code alerts + Google redirects to route developers to attacker infrastructure.</p><p>The flow adapts based on cookies and fingerprints users before serving a second-stage attack. Not your average phishing link:</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://socket.dev/blog/widespread-github-campaign-uses-fake-vs-code-security-alerts-to-deliver-malware" title="Widespread GitHub Campaign Uses Fake VS Code Security Alerts...">
<img src="https://cdn.sanity.io/images/cgdhsj6q/production/7d45a83cec4f3389b8cfdd4df4b43e623ec75502-1024x1024.png?w=1000&q=95&fit=max&auto=format" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://socket.dev/blog/widespread-github-campaign-uses-fake-vs-code-security-alerts-to-deliver-malware">
Widespread GitHub Campaign Uses Fake VS Code Security Alerts...
</a>
</h5>
<p class="card-text line-clamp-3">Widespread GitHub phishing campaign uses fake Visual Studio Code security alerts in Discussions to trick developers into visiting malicious website.</p>
</div>
<a href="https://socket.dev/blog/widespread-github-campaign-uses-fake-vs-code-security-alerts-to-deliver-malware" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://socket.dev/favicon-32x32.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />









<p class="d-inline-block text-truncate mb-0">Socket <span class="text-secondary">(socket.dev)</span></p>
</a>
</div></p><p><img
      src="https://board.circlewithadot.net/assets/plugins/nodebb-plugin-emoji/emoji/android/1f517.png?v=28325c671da"
      class="not-responsive emoji emoji-android emoji--link"
      style="height: 23px; width: auto; vertical-align: middle;"
      title="🔗"
      alt="🔗"
    /> <a href="https://bsky.app/profile/socket.dev/post/3mhvx4lgge22k" rel="nofollow noopener"><span>https://</span><span>bsky.app/profile/socket.dev/po</span><span>st/3mhvx4lgge22k</span></a></p><p><a href="https://mstdn.feddit.social/tags/Security" rel="tag">#<span>Security</span></a></p>]]></description><link>https://board.circlewithadot.net/topic/5f27660c-dda5-4310-8506-9538c10828ea/we-re-seeing-a-widespread-github-campaign-using-fake-vs-code-alerts-google-redirects-to-route-developers-to-attacker-infrastructure.</link><generator>RSS for Node</generator><lastBuildDate>Thu, 09 Apr 2026 19:09:19 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/5f27660c-dda5-4310-8506-9538c10828ea.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 31 Mar 2026 06:18:46 GMT</pubDate><ttl>60</ttl></channel></rss>