Yesterday I rcv'd a novel Github-based scam. An empty repo was made w/ 500 identical issues announcing a "GitHub × Gitcoin Developer Fund", each w/ 30+ users tagged (~16k devs got it).
It relied on a masked URL to github-foundation.com (recently reg'd) vs grants.github.com.
W/in ~1hr a user commented all 500 issues w/ a warning that went into the email thread for all of em. Big public service imo. And whatdya know, the repo disappeared super fast after that.