Gitloker attacks abuse GitHub notifications to push malicious oAuth apps

Published on June 10, 2024

Threat actors impersonate GitHub's security and recruitment teams in phishing attacks to hijack repositories using malicious OAuth apps in an ongoing extortion campaign wiping compromised repos. [...]