Please check your repos for suspicious "Upload Files" PRs ... And report them to GitHub

This triggers cryptomining jobs in GitHub Actions that will appear under your repo

Show thread

@lupyuen What's the point of making these? Actions on PRs execute with the resources of the owner, no? What's the advantage of making the PR on someone else's repo?

Follow

@2ck To evade detection maybe? Many repos are idle and can trigger jobs with this hack

Sign in to participate in the conversation
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.