People have programs that scan github uploads for AWS, etc credentials accidentally uploaded by victim and spawn images that mind crypto for the attacker’s.
https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_g...
https://www.theregister.co.uk/2015/01/06/dev_blunder_shows_g...