logo

Is this a supply-chain attack attempt?

Posted by maratumba |an hour ago |1 comments

maratumba an hour ago

I was looking into the issues in this -probably- abandoned library and noticed this account helpfully offering to take over the project. The account has no other activity than this post after it's been created 5.5 months before. Seems like it could be a supply chain attack (or maybe just some LLM agent raising github stars).

Does github have a mechanism for flagging suspicious accounts? Reporting doesn't seem like the right idea without any actual wrong-doing.