Fran Donoso @francisck.com · 01/11/2025I may have gone overboard on the Halloween goodies this year #halloween 030
Fran Donoso @francisck.com · 15/03/2025Okay 3rd (and last post) someone in the linked GitHub issue noticed that all of the tags in the project have been pointed to the malicious commit. The malicious commit was made by a "renovate" bot - perhaps its creds were compromised? 3/2 github.com/tj-actions/c... 220
Fran Donoso @francisck.com · 15/03/2025Image referenced above is attached to this post. The GitHub action ultimately outputs a double base64 encoded value that is the secrets it was able to extract. See the second image for what this output looks like in Github action logs (I blacked out some of the output). 2/2 110
Fran Donoso @francisck.com · 11/10/2023The judge: Why was your cat already wearing a hacker hoodie?!? 000