This is not new[1], but interesting that github didn't think about this when they set-up gh-pages. It's hard to blame them though. Security is easy to miss. Myself and many other people who use github, and who understand those issues, don't really think about it until someone points this out... [1] http://security.stackexchange.com/q/12412/7306 - just an example of a discussion about this very same issue from about a…
If I would consider it as a new attack I would call it Homakov Cookie Tossing Attack. Now it's just cookie tossing.