The Stack

A mystery threat actor is running an "abnormally" large freejacking campaign that taps GitHub, Heroku to mine crypto

Cybersecurity

A mystery threat actor is running an "abnormally" large freejacking campaign that taps GitHub, Heroku to mine crypto

Security researchers at Sysdig say that they have identified a previously unreported threat actor “using some of the largest cloud and continuous integration and deployment (CI/CD) service providers” in a massive “freejacking” campaign that makes use of trial accounts’ free compute to power cryptomining campaigns. Dubbing it PURPLEURCHIN, Sysdig