Overview

A large-scale campaign is targeting developers on GitHub with fake Visual Studio Code (VS Code) security alerts posted in the Discussions section of various projects, to trick users into downloading malware.

Organisations Involved

The following organisations are mentioned in relation to this incident: GitHub, Visual Studio Code.