Please check your repos for suspicious "Upload Files" PRs ... And report them to GitHub

This triggers cryptomining jobs in GitHub Actions that will appear under your repo

Show thread
Follow

@lupyuen What's the point of making these? Actions on PRs execute with the resources of the owner, no? What's the advantage of making the PR on someone else's repo?

@2ck To evade detection maybe? Many repos are idle and can trigger jobs with this hack

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.