The article hasn’t proven that the infection is in the GHCR Docker image, let alone the newest version. It only says that they had the image installed, then (unknown time later) noticed the infection. According to some messages on Hotio’s Discord server from 2023-11-25, qBitTorrent moved from fixed admin credentials to randomized at initialization. I think MrHotio’s message about that crypto miner was likely a joke a…
OP's system got compromised at some point; the images are clean.
Hell if he didn't want to post his clickbait he easily could have verified with a clean image on a known clean system