Attackers used GitHub for cryptomining, but the service has not yet closed the vulnerability

The popular source code storage service GitHub is investigating a series of attacks on its cloud infrastructure. Cybercriminals were able to infiltrate the company’s servers and use them for cryptomining. The press secretary of the service told The Record resource.

(The Record)

The attacks began in the fall of 2020 and were carried out through GitHub Actions, a service feature that allows users to automatically complete tasks and workflows when a certain event occurs in one of their GitHub repositories.

Dutch security engineer Justin Perdok told The Record that at least one of the attacks involves sending Pull Requests to make unwanted changes to other people’s repositories. The engineer noted that the attackers are targeting the owners of such GitHub projects, which process Pull Requests automatically, rather than manually.

(Justin Perdok)

As soon as such a malicious request is submitted, the GitHub system reads the attacker’s code and launches a virtual machine, which in turn downloads and runs cryptocurrency mining software on the GitHub infrastructure. Mr. Pedok noted that he was faced with the launch of up to a hundred cryptocurrency miners with just one attack – this created a huge computational load on the GitHub infrastructure.

Attacks, according to the specialist, occur randomly and on a large scale. He has identified at least one account making Pull Requests containing malicious code. At the same time, such activity of cybercriminals has been observed since at least November 2020, when a French software engineer reported the first case.

(Justin Perdok)

In an email to reporters, GitHub said it is aware of the activity and is actively investigating it – the same service reported to a French engineer last year. Nevertheless, the company seems to be just blocking the accounts of the attackers, and they are registering new ones. At the moment, the attack does not harm users’ projects and seems to focus solely on the abuse of the GitHub infrastructure.

If you notice an error, select it with the mouse and press CTRL + ENTER.

Related Posts

Property Management in Dubai: Effective Rental Strategies and Choosing a Management Company

“Property Management in Dubai: Effective Rental Strategies and Choosing a Management Company” In Dubai, one of the most dynamically developing regions in the world, the real estate…

In Poland, an 18-year-old Ukrainian ran away from the police and died in an accident, – media

The guy crashed into a roadside pole at high speed. In Poland, an 18-year-old Ukrainian ran away from the police and died in an accident / illustrative…

NATO saw no signs that the Russian Federation was planning an attack on one of the Alliance countries

Bauer recalled that according to Article 3 of the NATO treaty, every country must be able to defend itself. Rob Bauer commented on concerns that Russia is…

The Russian Federation has modernized the Kh-101 missile, doubling its warhead, analysts

The installation of an additional warhead in addition to the conventional high-explosive fragmentation one occurred due to a reduction in the size of the fuel tank. The…

Four people killed by storm in European holiday destinations

The deaths come amid warnings of high winds and rain thanks to Storm Nelson. Rescuers discovered bodies in two separate incidents / photo ua.depositphotos.com Four people, including…

Egg baba: a centuries-old recipe of 24 yolks for Catholic Easter

They like to put it in the Easter basket in Poland. However, many countries have their own variations of “bab”. The woman’s original recipe is associated with…

Leave a Reply

Your email address will not be published. Required fields are marked *