Do not immediately revoke your GitHub token. First, identify and remove the background service installed by the malware. Only after confirming the malware is completely removed should you proceed with token revocation and other standard incident response procedures.