@hypolite @musenhain @suprjami That's tricky phishing. 👿 At first, I wasn't able to recognize the different characters replacing the slashes. I would have probably clicked such a link, if it had appeared in a resource from a trustworthy source. 😅
Even the @ character wasn't suspicious as :mastodon: #Mastodon user profile URLs also use them, for example. Without directly comparing it to the same URL it's hard to distinguish the first one especially depending on the font:
https://github.com∕kubernetes∕kubernetes∕archive∕refs∕tags∕@v1271.zip ❌
https://github.com/kubernetes/kubernetes/archive/refs/tags/v1.27.1.zip ✔️