Hacked pipelines defaced Microsoft's WSL repository with pro-Palestine messages

https://github.com/microsoft/WSL/pulls?page=1&q=is%3Apr

124 points · 11 comments · view on lemmy.world

11 Comments

azron@lemmy.ml · 18 pts · 1y (4 replies)

Hacked pipeline? These are just pull requests anyone can submit them.

itsathursday@lemmy.world · 36 pts · 1y (2 replies)

They are authentic commits and PRs by real contributors that have been edited and renamed with the PR description changed.

azron@lemmy.ml · 7 pts · 1y (1 reply)

Oh that is mildly interesting, my mistake. So the actual commits didn't change but the pull requests are made to look like they are something else.

r00ty@kbin.life · 4 pts · 1y

I think the top one might be the culprit. But it might be the guy's account was hacked?

On his repo he has a fork of WSL and the repo is called "free-palestine", he tried to merge the branch "freedom". So that PR seems likely to be linked to this. Other than this, activity seems normal for a terminal githubber with 444 repos...

BlackEco@lemmy.blackeco.com · 9 pts · 1y

If you watch the PRs history, you can see that the user github-actions edited them. This user is the default one when a GitHub Action (the pipeline OP refers to) alters the repo. So someone probably submitted a pull request abusing the GitHub token when the Action ran on their PR.

itsathursday@lemmy.world · 7 pts · 1y

Thank you for your contribution to WSL.

No fatal errors have been found.

No suggestions have been found.

amino@lemmy.blahaj.zone · 5 pts · 1y

based

Zenlix@lemm.ee · 3 pts · 1y (2 replies)

How can such thing happen? Was an account hacked that had the permissions?

BlackEco@lemmy.blackeco.com · 3 pts · 1y

Most likely someone submitted a pull request that abused the GitHub token of the Action running on new PRs in order to edit all the other pull requests.

chobeat@lemmy.ml · -3 pts · 1y

It could also be an inside job. Anti-genocide resistance within Microsoft is quite strong and active.

imnapr@discuss.tchncs.de · 1 pts · 1y

based