this post was submitted on 08 Mar 2026
80 points (100.0% liked)

Open Source

45525 readers
251 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 6 years ago
MODERATORS
 

These scammers copy the text from new issues verbatim, and paste them in a new issue in a "support" repo. They tag the original author so they get notified.

They then use GitHub Actions to reply with a phishing link and email.

This particular repo has been up for a week and has done this to 113 people.

The link leads to a page that impersonates GitHub support. Every link on that page leads to a crypto scam.

If you stumble across such a repository, please report it. You can report this one here.

top 12 comments
sorted by: hot top controversial new old
[–] hperrin@lemmy.ca 46 points 1 week ago

Curse you, Team Rocket.

[–] XTL@sopuli.xyz 31 points 1 week ago (2 children)
[–] digdilem@lemmy.ml 10 points 1 week ago (1 children)

Surely this will re-occur anywhere there is sufficient footfall?

[–] glibg10b@lemmy.zip 9 points 1 week ago

GitHub's reporting functions are limited. For example, it's not possible to report the issue or the reply from GitHub Actions. And the form for reporting the whole repository is somewhat broken and annoying to use

[–] kyub@discuss.tchncs.de 9 points 1 week ago (1 children)

Yes. It always pains me when I see how tons of open source projects will not leave Github because of the network effect. Yes, it might be inconvenient... even punishing... but it needs to happen, especially after Microsoft bought Github. The ONLY way to counter the network effect (and contribute to meaningful change over time) is by NOT being part of the network effect. By remaining part of it, you're only helping Microsoft.

[–] hummy_bee@mander.xyz 4 points 1 week ago (3 children)

What alternatives are there? I am seriously unaware. Recommendations please

[–] glibg10b@lemmy.zip 8 points 1 week ago (1 children)

GitLab, Gitea and Codeberg

[–] melroy@kbin.melroy.org 4 points 1 week ago

Also try to run it yourself at home.

[–] shrek_is_love@lemmy.ml 1 points 1 week ago

I've been noticing that more and more projects are being hosted on Codeberg lately. Some examples:

[–] gwl@lemmy.blahaj.zone 5 points 1 week ago

on GitHub

Ah, there's your problem

[–] Bazell@lemmy.zip 4 points 1 week ago