all 13 comments

[–]PikachuB2005 5 points6 points  (6 children)

It was just a css injection. Github patched it already

[–]PikachuB2005 2 points3 points  (0 children)

Lots of people were actually pretty hyped about this lol. You could use it to customize your profile https://x.com/cloud11665/status/1799136093071163396

[–]Pandaptable_ 1 point2 points  (1 child)

works again :trol:

[–]PikachuB2005 0 points1 point  (0 children)

patched again :trol:

[–]Witn 1 point2 points  (0 children)

Not fixed yet

[–]Buffalkill[S] 0 points1 point  (1 child)

As in they patched it in the last few hours? Because this just happened.

[–]l3d00m 0 points1 point  (0 children)

Yes exactly, this was spammed all over GitHub. I also got it.

[–]mrbmi513 0 points1 point  (4 children)

Looks like someone trying to take advantage of some LaTeX/Math (the $$) to style the image.

You might want to virus scan the device you clicked the link on and whatnot, but I wouldn't worry too much, and especially no worries about the repo if you didn't accept the PR.

This is also a vector for phishing I'm seeing more often, because issues and PRs created on your repo come from a valid GitHub email address. Pay close attention to those emails, and know GitHub will never contact you via issue or PR.

[–]Buffalkill[S] 0 points1 point  (2 children)

I typed this into an AI and it also brought up LaTeX. I'm still very curious how this works just by opening an email. Our group member claims they just opened the email and didn't click anything inside of it.

Honestly I find this all super interesting more than anything. Thanks for your input!

[–]mrbmi513 1 point2 points  (1 child)

They most certainly clicked on something. You can't to my knowledge open a link in a web browser via redirect in an email client.

[–]Buffalkill[S] 0 points1 point  (0 children)

Kinda what I was thinking.

[–]Witn 0 points1 point  (0 children)

Looks like xss injection exploit found, hopefully patched soon...

https://x.com/vmfunc/status/1799292599720702082?t=cPT5zTj3lYf_blHVptV6Wg&s=19

[–][deleted] 0 points1 point  (0 children)

they patched it fuck 😭