Hi Folks,

Related to yesterday/today thread: Malicious package upstream: 
plasma6-applet-quicklaunch (6.5.80-3)

It seems GitHub as been fucked, please check your package upstream repos.

https://thehackernews.com/2026/10/credential-stealing-github-actions.html

Just spreading the word. 

Emiliano Gandini Outeda
emiliano-go[dot]com
emiliano.gandini[at]protonmail[dot]com

Attachment: publickey - [email protected] - 0xF759D6D4.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to