As the repo is was taken down is someone able to tell me when was the malicious commit pushed. Trying to get a timeline to see if any workflows using this action were trigger in that timeframe. Thank you
I believe it's everything since around 10pm ET last night. I would consider any runs in the past 24 hours to be suspect.
It should be easy to do with thr Github CLI tool and some bash scripting.
Not sure how easy it'll be to parse the logs to look for a base64 string but it shouldn't be that complicated either.