started · updated
GitHub hosts malware scam using copycat macOS app repositories
A widespread malware scam is proliferating on GitHub by using copycat repositories to impersonate popular macOS applications. The attackers create fake repositories for well-known software, including VLC Media Player, Figma, Malwarebytes, and 1Blocker, to exploit GitHub’s search engine optimization and ranking.
The scam utilizes a consistent template involving recently created anonymous accounts and fake support email addresses designed to appear legitimate. Users are directed to download links hosted on separate fraudulent GitHub pages, often containing malicious JavaScript. While some fraudulent repositories have been removed following reports, many others remain active.