# Security alert: social engineering campaign targets technology industry employees

DevFeed: [Security alert: social engineering campaign targets technology industry employees](<https://devfeed.tech/articles/security-alert-social-engineering-campaign-targets-technology-industry-employees-67948.md>)

Original publisher: [Read original article](<https://github.blog/security/vulnerability-research/security-alert-social-engineering-campaign-targets-technology-industry-employees/>)

Author: Alexis Wales

Published: 2023-07-18T14:43:24Z

Content type: news

Language: en

Sources: [GitHub Blog](<https://devfeed.tech/sources/github-engineering.md>)

Topics: [axios supply chain attack](<https://devfeed.tech/topics/axios-supply-chain-attack.md>), [npm security](<https://devfeed.tech/topics/npm-security.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Security research](<https://devfeed.tech/topics/security-research.md>)

Tags: [credentials](<https://devfeed.tech/tags/credentials.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [dependencies](<https://devfeed.tech/tags/dependencies.md>), [published](<https://devfeed.tech/tags/published.md>), [security](<https://devfeed.tech/tags/security.md>), [security-alert](<https://devfeed.tech/tags/security-alert.md>), [social-engineering](<https://devfeed.tech/tags/social-engineering.md>), [vulnerability-research](<https://devfeed.tech/tags/vulnerability-research.md>)

## AI overview

GitHub reports a low-volume campaign that uses fake or compromised social accounts to lure technology-sector employees into cloning repositories containing malicious npm dependencies. Those packages install malware that downloads a second-stage payload. GitHub says its own and npm systems were not compromised, and recommends scrutiny of collaboration requests, new packages, dependencies, and installation scripts.

## Source excerpt

GitHub has identified a low-volume social engineering campaign that targets the personal accounts of employees of technology firms. No GitHub or npm systems were compromised in this campaign. We're publishing this blog post as a warning for our customers to prevent exploitation by this threat actor.