HACKER Q&A
📣 aeharding

Is anyone else getting spammed via GitHub recently?


Earlier today, a number of people I know have been spammed via GitHub issues and discussions, using @-mentions. Push notifications and emails sent. Very annoying because the report process for spamming on GitHub is not that quick.


  👤 TranquilMarmot Accepted Answer ✓
Yes! I was disappointed at how many steps reporting the malicious user took. I think it was like 10 clicks to finally submit the report, almost like they wanted to make it difficult.

👤 ssss11
Oh, I thought the hot chicks were really for me…….. damn you github (and fb, email, TikTok, Twitter and so on….)

👤 blahblah1234567
Yep.

The content of the email was:

" Message me when you are free https://to.sv/SomeUUID

Hey All my photos and videos here https://to.sv/SameUUIDAsAbove "

Very suspicious. I searched the URL on a malicious link lookup site and found "7 security vendors flagged this URL as malicious"


👤 rpigab
Yes, on a random discussion about editing the README I never interacted with, on a repo I like (BurntSushi's ripgrep) but do not remember interacting with, no star, no follow, no fork or anything else from me (I should star it and interact though, it's awesome).

A lady mentionning something getting wet, many mentions including me and the same type of link others mentionned.


👤 metadat
Yes I also got one today.

Couldn't find any "report spam" or "report post" link.


👤 codegeek
Yes got it an hour or 2 ago. Totally unrelated and no idea how I got tagged.

👤 lfconsult
Yes, just happened this morning... First, I received a GitHub notification without tag (I even didn't know how is it possible) then I was tagged in a comment to a README "I’m completely nak*d Wanna see the photo" plus a link (obviously)...

Edit: It's in the "Discussions" GitHub tab.

Edit: Got a GH response:

"Our review of the account(s) and/or content named in your report has concluded. We have determined that one or more violations of GitHub’s Terms of Service have occurred and have taken appropriate action in response."


👤 david_allison
Yes, I contributed a small documentation fix to a service. I'm now assumed to be a maintainer and users tag me in issues whenever the service goes down.

These issues have hundreds of replies, and GitHub has UX problems on large issues: comments you're tagged in aren't immediately visible, which discourages reporting (it may take ~2/3 minutes to expand a conversation to find and report it).

It discourages future contributions to repos I don't maintain.


👤 signaru
Got one, the links and repo look legit (on first glance at least). But I have absolutely no idea why I am cc'ed on it.

I'm replacing the specifics with words in "<>", but here's the title of my mail from notifications@github.com:

Re: [/] (Discussion <#number>)



👤 meken
Yes I got my first ever GitHub spam today :(

👤 bosky101
I did start seeing unrelated repos under topics/x

👤 elforce002
Yes. Yesterday. It was right after I commented on an issue. This is the first time I get that. The interesting thing is that the spam had users that didn't comment on the actual issue.

👤 kobaroko
Is there some setting in GitHub to prevent this messages from coming?

👤 GabeIsko
Happened to me a few days ago. Added to a korean github, a lot of repositories that are called "pre-onboarding" or something. Anyone know what is going on?

👤 trashface
Same for me. Onlyfans and github have merged I guess.

👤 version_five
What kind of repos is this happening for? Like is it targeting personal projects, contributions to bigger open source projects, or something else?

👤 LinuxBender
Yes. I nuked my GitHub email canary. The spam comes across as a mail-list thread with a thread ID.

👤 sambhu
Yes, with random GitHub users mentioned and link to some adult malicious site

👤 4silvertooth
Yes, I got it just now, I haven't stared that repo, or have any mentions.

👤 nop_slide
Yep I literally just got one 10 mins ago and saw this thread.

👤 cjk
Yep. First time I’ve seen anything like that on GitHub.

👤 schemescape
Yes, just got one.

Edit: and another…


👤 eurticket
Yes

👤 martin-adams
Yes, happened just now

👤 jucaguirrear
yes

👤 masukomi
yup.