I don't know how new it is, but it first dropped on my radar about a year ago due to listening to the Risky Business cybersecurity podcast, not to be confused with the recent (and baffingly named (*)) podcast called 'Risky Business with Nate Silver and Maria Konnikova' (**) by dweeb Nate Silver. So I don't know how long it was going on the wild, and im talking about the windows button + r attack method and not the github comments, no idea how long they used comments as a vector. And yes that part is also good, like the addition of trust of github + quite an effective attack is clever. Shouldn't work on Real Nerds however.
*: The name means that at least one of they didn't [know|care|google] about the decades old cybersecurity podcast before naming their podcast that is true. Any of those is odd.
**: addition to above, the tagline of the podcast is 'a weekly podcast about making better decisions' Look inwards Nate, look inwards.
I was reminded of Risky Business and how some of the cybersecurity is sometimes relevant to this sub, which reminded me they talked about this Cryptocurrency people being actually rubber hosed