Major phishing campaign on GitHub using fake security alerts

Key summary
A large-scale phishing campaign is abusing GitHub Discussions to post fake Visual Studio Code security alerts that urge users to install updates via external links.
Thousands of nearly identical messages are posted across many repositories in minutes by newly created or barely active accounts, with large numbers of developers tagged to increase visibility.
The posts cite fictitious CVE identifiers and attackers impersonate well-known maintainers or security researchers to appear trustworthy.
External links (often to Google Drive) redirect through chains to attacker-controlled infrastructure where a JavaScript profiling page collects time zone, browser and operating system data.
The profiling data is forwarded to a command-and-control server to filter real victims from bots and researchers; no direct malware page or credential collection is present at this stage.



