TGViewer
Fsecurity | HH Fsecurity | HH @hellohackingteam · 2.06K subscribers
Post #7682 132

Forwarded from 1N73LL1G3NC3

The Phishy GitHub Issue Case

As I’m interested in initial access, and more specifically in phishing, I started looking for ways to target developers. What platform every developers uses today? You guessed it right (or just correctly read the title of this blog post) : GitHub. It is advertised as “a platform to create, store, manage and share code”. Every developer has a GitHub account and getting access to it mean getting access to their code. However, I was looking for lesser-know phishing technique, that doesn’t employ the usual Attacker-in-The-Middle approach. I stumbled upon several articles mentioning Fake Security Alerts using GitHub issues. Naturally, I decide to take a look at what it was. So let’s see how to setup this scenario for your next phishing campaign!

MalGitApp

A simple OAuth App designed to capture OAuth tokens when users authenticate through GitHub OAuth flow.
More from @hellohackingteam
  1. Oct 9, 2026🔑 SrHollow - дамп LSA secrets без касания к LSASS Очередной дампер секретов Windows, но с…
  2. Oct 9, 2026Глобальная панель разведки в реальном времени, которая агрегирует отслеживание полетов в р…
  3. Oct 9, 2026Discord сервер 👆🏻Тут можно пообщаться и найти много полезной информации 🦈
  4. Oct 9, 2026Собрал GitLab видео PoC's 🔍 При ресерче различных CVE под GitLab появилась необходимость…
  5. Oct 9, 2026🔗 Ссылка: https://github.com/Casualtek/Ransomchats
  6. Oct 8, 2026🔗 Ссылка: https://codeby.net/threads/analiz-kiberintsidentov-v-rossii-2025-proval-signatu…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →