# GitHub comments abused to push malware via Microsoft repo URLs

**URL:** https://discuss.privacyguides.net/t/github-comments-abused-to-push-malware-via-microsoft-repo-urls/17963
**Category:** Off Topic
**Tags:** software
**Created:** 2024-04-20T19:47:40Z
**Posts:** 3

## Post 1 by @anonymous176 — 2024-04-20T19:47:40Z

> **[GitHub comments abused to push malware via Microsoft repo URLs](https://www.bleepingcomputer.com/news/security/github-comments-abused-to-push-malware-via-microsoft-repo-urls/)**
>
> A GitHub flaw, or possibly a design decision, is being abused by threat actors to distribute malware using URLs associated with a Microsoft repository, making the files appear trustworthy.

---

## Post 2 by @jonah — 2024-04-20T20:08:28Z

I’ve always wondered whether those uploads get stored on their CDN forever, even if you don’t post the comment. It’s weird to find out they do, surely that’s a massive waste of storage on their end.

---

## Post 3 by @Sprout3425 — 2024-04-21T02:04:28Z

Also, it is un-environmentally conscious, never liked Microsoft, profits over the environment.
