Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Hackers Use GitHub Notifications to Impersonate Y Combinator and Steal Wallet Funds

Recent sophisticated phishing attacks have targeted developers and startups by impersonating Y Combinator through GitHub notifications.

Recent sophisticated phishing attacks have targeted developers and startups by impersonating Y Combinator through GitHub notifications.

Attackers registered multiple GitHub accounts and repository names closely resembling “Y Combinator,” such as “ycombinato,” “ycombbinator,” “yccombinator,” among others. These accounts created hundreds of GitHub issues per minute, each tagging numerous random users. The notifications were designed to resemble official Y Combinator communications, often mentioning a supposed selection for funding or an authorization process. Victims received emails and GitHub notifications, sometimes with follow-ups asking users to verify their wallets or deposit funds for the next steps.

Attackers also deployed GitHub Apps, such as “ycombinatornotify” and “mail-notifaction-automatic,” to increase the perceived legitimacy of the messages. The scheme leveraged both GitHub’s notification system and emails, using automated scripts until the repositories were reported and deleted or rate-limited by GitHub.

Many victims reported being redirected from these GitHub notifications to phishing domains like “y-comblnator.com” and similar lookalikes. These pages mirrored Y Combinator branding but were designed to collect wallet credentials or request crypto deposits. Users noticed these domains were typo-squatted, substituting letters and adding hyphens to evade detection.

Recent sophisticated phishing attacks have targeted developers and startups by impersonating Y Combinator through GitHub notifications.
Sam Quinlan · Thehackingpost

Some reports indicated ongoing suspicious activity even after initial spam repositories were removed, with further notifications from newly created accounts and repositories. The attackers constantly adapted their approach, launching new campaigns before previous ones were taken down.

Users shared warnings and mitigation tips on forums, tagging the official Y Combinator security team and using GitHub’s abuse reporting system. Affected individuals also submitted the fraudulent domains to browser and search engine phishing protection lists. To remove notification spam lingering in GitHub, users leveraged API workarounds, as the UI did not display these messages properly.

GitHub has since responded by deleting scam repositories and user accounts, but phishing notifications and fake domains may persist. This phishing campaign highlights how cybercriminals increasingly exploit trusted service notifications and mimic reputable brands to bypass normal user skepticism.

Advertisement

Developers and startup founders are urged to stay cautious, verify communications with organizations directly, and report suspicious activity swiftly.

Based on reporting by GBHackers.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories