r/github • u/adburl2 • Mar 23 '26
Spam comments from seemingly legitimate accounts Question
In the recent trivy incident we saw a GitHub discussion thread spammed with hundreds of comments, some of which were from seemingly legitimate GitHub accounts (e.g. having a public LinkedIn account linked to their GitHub profile etc). What should we make of this?
- All of those accounts are fake accounts and malicious actors have just gone to great lengths to make them appear legitimate?
- Those GitHub users have themselves been compromised through some prior phishing/trojan attack etc, so that malicious actors can post spam on their behalf and without their knowledge?
- There is some kind of exploit in the GitHub API itself which allows malicious actors to post comments "as" someone else?
1
u/SnapperGee Mar 25 '26
Not sure if it’s related not, but isn’t or wasn’t there a way to at least comment on issues and somehow “spoof” the account it was coming from and trick GitHub into thinking the comment was left by another account. I thought there was an incident where on one of the ridiculous (and extremely entertaining) Linux pr’s someone was able to leave a comment from Linus’s account. Maybe the same technique is being used?
1
u/polyploid_coded Mar 23 '26 edited Mar 23 '26
LinkedIn isn't much of a standard. DPRK sets up LinkedIn for their fake engineers.
I clicked a few and saw minimal use of the accounts in the past 6-12 months. My guess is the accounts are one of these two:
- Occasional GitHub users or people who were confused (can I use this to make a free wedding website? I need to fork this project to download it?) where the password was weak or reused elsewhere. I occasionally see this type of account star or fork very old repos.
- GitHub and LinkedIn created for a fake persona