I got a spam message with a phishing link.... Via Github? Seriously? Are we really doing this?
Not a completely unusual comment.... From the URL it was very obvious that this was a phishing link though. Curiosity got the better of me. The site shows you a "cloudflare" captcha. OK, let's click the checkbox. The usual loading animation starts, then this is shown:
Yeah ok, right....
I'm actually a bit impressed with this, these captchas are so common, I didn't even really think about checking the box. But of course, that interaction means the browser will allow the site to add something to your clipboard.
But like.... Why distribute it via Github? I cannot think of a worse audience to try and con into "paste something random into your windows console". Am I just being naive here? Is this something common I somehow never experienced before?
Oh god
Although... Do you think VideCodersTM read github issues?