• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Github comments used to push malware via Microsoft repo urls

Joined
May 13, 2010
Messages
5,715 (1.12/day)
System Name RemixedBeast-NX
Processor Intel Xeon E5-2690 @ 2.9Ghz (8C/16T)
Motherboard Dell Inc. 08HPGT (CPU 1)
Cooling Dell Standard
Memory 24GB ECC
Video Card(s) Gigabyte Nvidia RTX2060 6GB
Storage 2TB Samsung 860 EVO SSD//2TB WD Black HDD
Display(s) Samsung SyncMaster P2350 23in @ 1920x1080 + Dell E2013H 20 in @1600x900
Case Dell Precision T3600 Chassis
Audio Device(s) Beyerdynamic DT770 Pro 80 // Fiio E7 Amp/DAC
Power Supply 630w Dell T3600 PSU
Mouse Logitech G700s/G502
Keyboard Logitech K740
Software Linux Mint 20
Benchmark Scores Network: APs: Cisco Meraki MR32, Ubiquiti Unifi AP-AC-LR and Lite Router/Sw:Meraki MX64 MS220-8P
Just read this and it's very scary...

Seems like github refuses to do anything to mitigate the issue either... it's been like this for months.
 
Joined
Apr 21, 2022
Messages
48 (0.06/day)
I know how to fix this, everyone mass upload files to every public repo. Maybe Microsoft will notice when Github needs 10000x more storage.
 

kacperoo29

New Member
Joined
Sep 26, 2021
Messages
9 (0.01/day)
Seems like a non-issue. The files don't get uploaded to source tree. It gets uploaded as an attachment just like log files would be. Wouldn't be surprised if nothing is done about it more than an option to report attachments as a malware.
 
Joined
May 7, 2020
Messages
39 (0.03/day)
Seems like a non-issue. The files don't get uploaded to source tree. It gets uploaded as an attachment just like log files would be. Wouldn't be surprised if nothing is done about it more than an option to report attachments as a malware.
Problem is that those files are attached to nothing, only way to find them is if somebody is trying to screw you by sending a link. And the link looks legit
 
Top