Report post

Is GitHub mining cryptocurrency?

Code Repository Hosting Service GitHub Launched an Investigation Regarding a Series of Attacks Aimed at Abusing Its Infrastructure for Illicitly Mining Cryptocurrency. Let's get started! Software developers have reported a series of malicious activities on their repositories, having the end purpose of mining cryptocurrency.

Are GitHub actions a threat?

Repositories use GitHub Actions to facilitate CI/CD automation and scheduling tasks. However, this particular attack abuses GitHub's own infrastructure to spread malware and mine cryptocurrency on their servers. The attack involves the threat actor forking a legitimate repository that has GitHub Actions enabled.

Can GitHub actions Cron be used to mine cryptocurrencies?

Chartier describes how an attacker can abuse GitHub Actions cron feature to create new commits every hour with the aim to mine cryptocurrencies. Because developers can run arbitrary code on our servers, they often violate our terms of service to run cryptocurrency miners as a "build step" for their websites.

How many crypto-miners attack GitHub?

Indeed, security researchers have reported observing attackers initiate as many as 100 crypto-miners with a single attack, placing massive computational pressure for GitHub's infrastructure. So far, these attackers seem to be striking at random and at scale.

The World's Leading Crypto Trading Platform

Get my welcome gifts