The article reveals a malicious software attack method known as a 'kill switch', where attackers install the gh-token-monitor script on the victim's machine, use the stolen GitHub token to periodically check its status, and once the token is revoked, it triggers the deletion of the user's local files.
入选理由:攻击者利用 gh-token-monitor 脚本每 60 秒轮询 GitHub API,检查被盗 token 的状态。
