GitHub Discussion Boards Weaponised for Developer Malware Distribution via Spoofed VS Code Alerts
Attackers are posting fake VS Code security alerts in GitHub project Discussions to trick developers into downloading malware. The campaign exploits trust in legitimate tooling warnings and the open nature of GitHub's collaboration features.