GitHub is being abused to distribute the Lumma Stealer information-stealing malware as fake fixes posted in project comments.


BleepingComputer
GitHub comments abused to push password stealing malware masked as fixes
GitHub is being abused to distribute the Lumma Stealer information-stealing malware as fake fixes posted in project comments.
