Telegram (AI) YouTube Facebook X
Ру
GitHub servers used for cryptocurrency mining

GitHub servers used for cryptocurrency mining

The GitHub service for hosting IT projects is investigating a series of attacks on its cloud infrastructure, which allowed unknown actors to use the company’s servers to mine cryptocurrency. The Record reports.

Attacks have continued since autumn 2020. Cybercriminals abuse the GitHub Actions infrastructure. It enables automating workflows when certain events occur in GitHub user repositories, for example [simple_tooltip content=\”request to merge changes from a user branch into the main branch of the original repository\”]Pull Request[/simple_tooltip].

“The attack involves branching a legitimate GitHub repository, adding malicious actions to the source code, and then submitting a pull request to merge into the original repository,” said information security expert Justin Perdok.

GitHub’s systems then read the malicious code and spin up a virtual machine with applications for cryptocurrency mining.

According to Perdok, in a single attack the attackers can deploy up to 100 crypto miners, creating enormous computational loads on GitHub’s infrastructure.

One of my repo’s just got hit with a similar attack. Account in question has a bunch of other open PR’s that currently have miners running. https://t.co/PZxApykuO9 pic.twitter.com/zugl7mFK0K

— Justin Perdok (@JustinPerdok) April 2, 2021

GitHub representatives said the incident did not affect user data or their repositories. The company blocks attacker accounts, but they are actively creating new ones.

Earlier ForkLog reported that an installer of a hidden miner was found in the cheat code for Call of Duty.

Subscribe to ForkLog news on Telegram: ForkLog Feed — the full news feed, ForkLog — the most important news, infographics and opinions.

Подписывайтесь на ForkLog в социальных сетях

Telegram (основной канал) Facebook X
Нашли ошибку в тексте? Выделите ее и нажмите CTRL+ENTER

Рассылки ForkLog: держите руку на пульсе биткоин-индустрии!

We use cookies to improve the quality of our service.

By using this website, you agree to the Privacy policy.

OK