malware report ignored , stolen account used to infect other people #207814
Replies: 1 comment 1 reply
|
I’m so sorry you’re going through this—dealing with an account takeover is stressful enough on its own, let alone watching someone use your account to spread malware to others. Thank you for raising the alarm and trying to protect the community. Because standard support queues can unfortunately take time, here are the most effective ways to escalate this critical security threat right now: Use the direct Abuse reporting line: Instead of a standard ticket, submit a report via the GitHub Report Abuse page under "Account Compromise" or "Malicious Activity." Make sure to mention in the submission title that the account is actively distributing malware. Highlight your ownership proof: Be sure to state clearly in your report that you still hold the original SSH private keys, can confirm your historical login IP/location, and have access to prior billing or account details. Escalate publicly to Security Teams: Tag @githubhelp and @GitHubSecurity on X (Twitter) with your abuse ticket reference number. Security posts highlighting active community danger generally receive much quicker visibility. Help warn the wider ecosystem: If you haven’t already, consider submitting the malicious payload to VirusTotal and CISA/US-CERT. This helps security vendors block the malware upstream while GitHub works on locking down the account. |
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
Discussion Type
Question
Discussion Content
I never thought I'd have to make a post like this.
My main GitHub account was compromised after I downloaded a software from a github repository that turned out to contain malware a couple days ago. The attacker took over my github account and then changed its username to impersonate a popular game modding tool.
And they're still using it. The account is now being used to distribute the malware to other people, while looking like a legitimate project, it even has my history of contributions to other open source projects to make it look real.
I've reported the github repository I download malware and my old account to GitHub support multiple times since then. Nothing happened. No meaningful response. The account is active and still under the attacker's control.
I have evidence showing what happened. My email linked to the account has been changed but I still have the ssh private keys I used. And I login from the same location for more than 5 years.
What really bothers me is that this has gone beyond my account being stolen. Someone is actively using a compromised GitHub account to make malware look legitimate and potentially infect more people.
If you know how to handle this, please point me in the right direction.
And if you're downloading game tools from GitHub, please be careful what you have got, I scanned it with windows defender and it passed (I uploaded it to Microsoft malware analysis already). A project can look legitimate and be compromised.
I just don't want someone else to get infected because nobody dealt with this.
All reactions