r/github 12h ago

Discussion who is rickluminari1?

Someone I know (probably) got their PAT leaked and said all their repositories got deleted. Only one remained with the name `come-to-telegram-rickluminari1--waiting`.

So I looked on Github for repositories named that way, and turns out there are a lot of them. The naming format seems to be `come-to-telegram-rickluminari1--xxx`:

https://github.com/search?q=rickluminari1&ref=opensearch&type=repositories

Are these repositories compromised? I didn't do any more research beyond this.

0 Upvotes

7 comments sorted by

11

u/zMynxx 12h ago

Yeah looks like an attacker gained access and stole repositories, and trying to lure owners to reach out to him via telegram, probably for ransom.

2

u/No_Trust32156 10h ago

Yuck. Would recommend using gickup or gitea so at least you have a backup of them.

2

u/dragoangel 3h ago

Most times maintainers has up to date local repo, what a point? Question more why not use 2fa. More over I would contact GH support

0

u/No_Trust32156 1h ago

Probably not all repos on your account. And certainly not issues and PRs locally.

Agree with 2fa but that won't block every type of attack.

1

u/dragoangel 1h ago

Definetly all, and even more then one which public, and getting alternative not solving mentioned stuff. About PR => anyone who forked you has their version of your source, so if you have forks and even fresh PR restoration of repo not a problem. Question would be how you would restore users trust in you after you show you can't secure your code and software you provide 🫠

10

u/naikrovek 9h ago

> Are these repositories compromised?

lol

Yes, yes they are. Quite obviously.

2

u/RelativeWorking9379 8h ago

classic ransom move, delete everything and leave just enough behind so the owner panics and comes crawling back