logoalt Hacker News

mkeeteryesterday at 5:27 PM3 repliesview on HN

A repository search shows 2.2K repos with the text "A Mini Shai-Hulud has Appeared", all created within the past day:

https://github.com/search?q=A%20Mini%20Shai-Hulud%20has%20Ap...


Replies

rhdunnyesterday at 5:35 PM

The repository names all look like two terms/words from dune (harkonen, mentat, ornithoptor, etc.) followed by a number. This would indicate that the account (possibly GitHub auth/actions token) has been compromised and then used to create the repository.

avaeryesterday at 9:40 PM

Why can't GitHub get on the case and just block any repo where the README matches the regex? I thought they'd have learned their lesson the last time it happened.

This malware isn't even trying. Then again it's Microsoft so they're not even trying either.

show 2 replies
spate141yesterday at 5:28 PM

what's this all about?

show 2 replies