Email or username:

Password:

Forgot your password?
Ed Summers

I caught someone using a pull request against one of my GitHub repositories to trigger crypto-currency mining via a GitHub action. I took a snapshot of it with archive-web-page here after reporting it to GitHub:

inkdroid.org/web-archives/gith

It seems like this is a thing now: bleepingcomputer.com/news/secu The only way to turn it off is to only run actions that are defined by the repository?

4 comments
Ed Summers

FWIW I'm glad I took a snapshot of the pull request pages with archiveweb.page because GitHub have deleted the PR, so it's like it never existed.

Ed Summers

Another "user" started doing this too, so I guess my whitelisting of allowed actions wasn't enough to block the shell commands in the action. I'll just have to disable actions altogether for the moment.

GitHub have since added a form option for cryptocurrency mining when reporting abuse:

Go Up