The Microsoft-owned source code collaboration and version control service reported the campaign, which it calls Sawfish, on Tuesday 14 April. Users were reporting emails that tried to lure them into entering their GitHub credentials on fake sites for a week before. The phishing campaign lures victims to domains that look similar to GitHubs at first glance but which the company doesnt own, such as git-hub.co, sso-github.com, and corp.com. Other domains misspell the i in GitHub with an l, like glthub.info.”]
Source: https://nakedsecurity.sophos.com/2020/04/17/github-users-targetted-by-sawfish-phishing-campaign/