Beware, there is an ongoing spambot attack in #GitHub issues in several projects were random people suggest "the fix" is to download a random file from mediafire.com. Like this:
@bagder ah, I got one of those. It seemed to be of low enough priority to safely ignore for the moment, but I now know to ignore it forever. Thanks.
@bagder mediafire dot com? that's a name I haven't heard in a long long time
@brunoph missed chance for a StarWars meme.
@bagder Does GitHub really not have any other way to mark comments but as "Abuse"?
@bagder we got this in fwupd too!
@bagder finally they have arrived to GitHub 
@bagder I got one of those this morning, but GitHub seems to have yanked it away between the time that I got the email notification and when I "WTAF?" navigated my way to the issue page.
@bagder Also had one of those yesterday.

@bagder Got it too on my repo. Downloaded it for science. It contains an exe with some dll.

The "FastRsync.dll" lib makes me think this tool will suck crypto and secrets out of your computer, fast.

@bagder just encountered that last guy lol. Reporting them does seem to get them banned pretty quick. I reported two and they were both banned within about 10 minutes.
@bagder this has been happening all week. I've had to limit interactions on a org with 300 repos, because the bots keep triggering each other with activity

@bagder

@GossiTheDog

a chorus of voices slightly offset from each other but numerous

"to fix your trouble..."

I tried to install the fix but I seem to be required to install Wine for it. Is there some project helping me install windows malware faster on linux? 😆
@grin I know you are joking but be careful. I have heard of malware that can actually function when run via Wine.

@draeath True. The joke was actually "I have to install Wine for the malware" since I don't have it. It's like the joke about <SMALL_POOR_NATION> virus: "I am a virus from <S_P_N>, we're too poor to write the infection part so please copy me everywhere and delete some files".

If we're serious then I would actually use a VM with windows on it, with no active network devices, since Wine is not very contained.

@grin
Sure! Let me find a link to it...
@bagder I also got those comments, with random comments saying to download a binary from Dropbox..!
@bagder This seems like a trivial pattern for Microsoft to nuke, but that's not a great sign.
@bagder mediafire.com my behated💔
Nothing good has ever come out of that website
@bagder seen this across repos and orgs the last week as well. Just
Report, use moderation (sad) or?
@bagder blocked a dozen of so of these the last two days

Gee, the move to microsoft and port to React sure are improving things!
@bagder Has some serious "miley-cyrus-new-album.bat" vibes

@bagder I grabbed the the file hosted on MediaFire. It is a Lumma Stealer per Triage.

https://tria.ge/240828-ry56astflp/behavioral1

lumma | 14fa452afcc4ff5ee00c88e603f670af754af1f8d0f53ae7cbaaa4b8c44afe1d | Triage

Check this lumma report malware sample 14fa452afcc4ff5ee00c88e603f670af754af1f8d0f53ae7cbaaa4b8c44afe1d, with a score of 10 out of 10.

@bagder I saw these start to pop-up in llvm issues yesterday.

It is troubling to see it is more widespread.

@bagder the answer is never download a file from a file hosting site
@bagder Ah, yes, say that and was puzzled by it.

@bagder lol this is hilarious.

More people need to explore other platforms for hosting their code. Something a little more self-sovereign.

@bagder
you can use codeberg instead of github.
There is a low probability to find spammer and hacker 👍
@bagder I saw one of these with a link to Dropbox. Dropbox took the link down before I even saw the comment and the comment was removed very shortly after