Has anyone taken a look at the binaries themselves to see what they do and how they differ from the official releases?
My findings as they go are being shoved into a blog post: https://grh.am/2018/a-look-at-the-compromised-gitea-release/
> Most of go-gitea organization repositories new release&tag was created with name 0 and added install.exe binary (13KB in size) to that release that was malicious (from our analysis contained crypto currency miner)
https://github.com/go-gitea/gitea/issues/4167#issuecomment-3...