I use community version of Drone (latest) and run drone & drone-runner in docker on my own server.
It work many years ok, until this month.
When I saw this picture at Grafana - I was surprised.
Every drone-xxxx container running running some garbage (i think - its mining).
I haven’t screenshoots of commands inside docker but i can replay this when i start my drone server again and wait some time)
I use Github authentication to the admin side and don’t understand where is hole to my server?
Same problem here. What I have found is that there was a user in my user management page on https://drone.xxxx.com/settings/users which had the Role user (so no Admin at least). I inspected some of the files in the container - they included base64 encoded commands, which seem to resemble some kind of bitcoin miner (don’t know for sure, but the URLs in the commands seem to be crypto related).