Hacker News new | past | comments | ask | show | jobs | submit login

You're right, it's creating commits but it's not just creating GHAs. It's also directly altering the targetted project's javascript to steal credentials from end users using the project. (Edited with correction as below.)

> it's not creating GHAs (sic)

… the OP includes a screenshot of a malicious GHA workflow that exfils secrets. (In addition to altering the targetted project's JS.)

Thanks for the correction. I only read the text.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact
