The injected malware code came from the PR branch name, called by a Github action that was misconfigured.
Hopefully that's an exploit path they'll close soon, if they've not done so already.
So technically, all environment variables are unsanitized and this was only the first problem in a list of bugs. This bug specifically used the "pull_request" event/action because it is automatically executed without any chance of stopping it, and was using details exposed via the pull requests head.ref.
Next up: git usernames and emails that use shellcode injection names, because github probably won't introduce sanitization to all variables/inputs now.
This is a prime example why you should never ever use a shell to log arbitrary data.
These protections (WAF for SQL/XSS, branch names for this) will never be enough. The code/logic must be secure, any additional layer is not enough since the actual target must be secured.
Developers will do it if its necessary, and it is. These situations are just proving it is necessary.
untyped strings, untyped strings everywhere
and they're directly executed, with untrusted user input templated in, with full release privileges
the entire thing is insane
to think pypa deprecated pgp offline signing for this...