Analysis conducted on July 28, 2026, identifies madushka1983-oss.github.io as an active phishing infrastructure hosted on GitHub Pages. The domain currently resolves to 185.199.110.153, an IP address associated with GitHub's content delivery network. Despite returning an HTTP 404 response with the page title 'Site not found · GitHub Pages', the domain remains flagged by six security vendors on VirusTotal and appears on two blocklists: PhishDestroy and OpenPhish. No nameservers are configured, which is atypical for legitimate GitHub Pages deployments and may indicate an abandoned or misconfigured phishing attempt.
The domain was registered through GitHub, Inc., and no evidence suggests it was transferred or compromised. The absence of visible content does not confirm inactivity; phishing pages may be concealed, dynamically loaded, or accessible only via direct links not indexed by public scanners. The lack of nameserver records could also reflect an attempt to evade detection or a temporary disruption in the attack chain. Defenders should treat this domain as high-risk.
Network-level blocking is recommended for the domain and its resolving IP. Security teams should monitor for any changes in HTTP status, page content, or additional detections, as the infrastructure may be repurposed for future campaigns. No brand impersonation or specific phishing kit has been confirmed at this time, and the exact content of the site remains unanalyzed. Further investigation into associated payloads, redirect chains, or linked domains is advised.