This is pretty crazy. A shell injection via a PR with a malicious branch name exploiting the github actions CI code to inject crypto miner into the release artifacts. Clever but it's pretty sad that the project maintainers fell for it.
1) Decide to use the highly risky `pull_request_target` Actions trigger instead of the much safer `pull_request` trigger, 2) include in their Actions a script, executing in an environment with write access to the repo and access to repository secrets, which executes untrusted input (the branch name).