We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.
You must be logged in to block users.
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Proof of Concepts for malicious maintainers: How to Tamper with Releases built with GitHub Actions Worfklows, presented at fwd:cloudsec Europe 2025
Shell 85 5
This terraform provider can be used to get remote code execution by injecting a dummy resource in a writeable state file.
Go 64 3
This GitHub Action sends a reverse shell from a runner via Azure Storage Account blobs
Python 39 3
A GitHub Action that exfiltrates secrets and environment variables
1 1
There was an error while loading. Please reload this page.