13 ms·
Malicious code added to 35k GitHub repos, leaking user environments
- robertwt7 4y agohow is this affecting people if the clone does not open PRs to the original one? so this will send data to the hacker's network if we clone and build the wrong repo right?
- mcraiha 4y agoThey have attacks for different programming languages and environments. So not just a single target (e.g. npm) attack.
- muppetman 4y agoHow would code like this make it into so many repos? People accepting pull requests and not properly reviewing them? Or is there something even worse about this attack?
- pcmonk 4y agoMost of them don't seem to come from pull requests, I wonder if it's paired with a bunch of compromised github accounts?
- bonzini 4y agoNot compromised, just created by the attacker.
- deleted 4y ago[deleted]
- stevelacy 4y agoMany of the repos I found were clones of valid projects with same names under new orgs and new users. For instance, this projects is valid: https://github.com/scala-network/GUI-miner https://github.com/scala-network/GUI-miner and it's infected clone: https://github.com/stellitecoin/gui-miner https://github.com/stellitecoin/gui-miner GPG signed commits by the legitimate users do not contain the malware
- laserlight 4y agoConsidering that only clones are affected, your original tweet is downright wrong. None of the listed projects (python, js, bash, docker, k8s) are affected. Anybody can fork a repository to introduce malware.
- eurasiantiger 4y agojs is a project?
- laserlight 4y agoYou're right. It's not. I just copy-pasted the list from the tweet. I assume that the author meant to write jq.
- rvz 4y agoOh dear. This is a gigantic disaster. If lots of software released today haven't been pinning their versions on release (especially Electron apps) or signing their commits if they are open-source, then this is a chaotic supply chain attack waiting to happen and is more worse than I thought. But really it is yet, another reason to avoid GitHub entirely and just self-host using GitLab or Gitea.
- szundi 4y agoThe last paragraph is orthogonal to the problem that an npm install poses here, wherever your repo is.
- jhugo 4y agoYou may have misunderstood (understandably, because the tweets seem to be deliberately misleading). These are malicious commits in forks of repositories. There is no supply chain attack unless you make a habit of taking random forks of popular projects from GitHub and inserting them into your supply chain.
- nicce 4y ago> There is no supply chain attack Actually yes, this is all about supply chain attacks. Typosquatting is one of the most common methods. It goes under this category.
- __alexs 4y agoSpam is not a problem GitHub has ever had to seriously face so far but this sort of attack does seem like it could catch some users casually googling for libraries. If you impersonated all these real repos, made npm, pypi packages for them etc and also updated the readme I think you could catch some people off guard.
- nicce 4y agoThis is a real problem indeed. There have been reports about successful ones. https://www.theregister.com/2022/07/06/npm_supply_chain_attack/ https://www.theregister.com/2022/07/06/npm_supply_chain_atta... https://www.idstrong.com/sentinel/npm-packages-info-stolen/ https://www.idstrong.com/sentinel/npm-packages-info-stolen/
- drekipus 4y agoThis is that thing where people can put anyone in as the commit author, thus impersonating the original creator right? Seems like the solution is "don't just copy random github urls into your code" ?
- macintux 4y agoThis is also a problem for enterprises. I’ve seen commits from root, ec2-user, etc: GitHub knows who’s pushing a commit even if git doesn’t, and it’s maddening that at least for enterprise accounts they don’t carry that identity into the metadata.
- iforgotpassword 4y agoThat would change the commit hash, at least if you want it to survive a clone of the repo. Of you'd store it externally so that it would only be able to be shown in the webui then it's of limited use, but maybe better than nothing.
- xrisk 4y agoI feel the commit data could be extended to include some metadata that isn’t used to compute the hash. GitHub could then make use of this data to populate whatever. (Not sure if such a field already exists in the commit blob)
- Karellen 4y ago> I feel the commit data could be extended to include some metadata that isn’t used to compute the hash. That's not how git works.
- xrisk 4y agoI’m somewhat familiar with how git works. In my understanding, a commit is just a blob combining the commit information and a tree blob, hashing them together to create a commit id. This design doesn’t preclude the usage of additional information in the commit blob that isn’t used to compute the hash. (Think for example how file access times do not affect its hash)
- jwilk 4y ago> So far found in projects including: crypto, golang, python, js, bash, docker, k8s Huh? What does that mean?
- sschueller 4y agoIt appears what is infected are forks of those repos but not the originals.
- jwilk 4y agoWhat would make sense for golang, python, docker, k8s; maybe even bash if you squint a bit. But what's the repo for "crypto" or "js"?
- skrebbel 4y agoThe author is being obtuse. They mean that clones have been made of those projects that include malicious code. It's like if I make a copy of the New York Times website but replace the cover image with nudity and put it on a different URL and someone tweets "omg NYT has nudity on the front page" and clarifies, vaguely, 10 tweets down that it was actually not the real NYT but a clone. I'm not convinced that the author is spinning it this way on purpose (ie for maximum emotional effect / retweets / internet points) or if it just comes from being too close to the subject matter, but it's pretty misleading either way.
- baliex 4y agoRiiight, that makes a LOT more sense. This would have been HUGE if the actual repos were infected and it wasn’t even at the top here at HN. I was very worried for a minute there, your comment has calmed me right down. Thank you!
- vishnugupta 4y agoThis should be the top comment on this thread.
- bonzini 4y agoSomebody should DDoS ovz1.j19544519.pr46m.vps.myjino.ru... (mostly kidding)
- mike_d 4y agoI admire the desire to help, but looking at flow logs to that IP address is how people are going to determine if they have compromises in their environments. Excess traffic to the IP will just muddy the water.
- ache7 4y agomyjino-ru is just a virtual hosting provider. j19544519 - seems to be the username on this hosting.
- raggi 4y agoThis code does more than leak environments. The go code pulls down arbitrary text and passes it to sh -c, example: https://github.com/zerops-io/zcli/commit/0396ee57bc0e5e0b12323aac7a240c4563488f9b#diff-c444f711e9191b53952edb65bfd8c644419fc7695c62611dc0fb304b4fb197d6R50 https://github.com/zerops-io/zcli/commit/0396ee57bc0e5e0b123...
- 3np 4y agoTL;DR: These are forks by unknown people containing malware. I see no indication in the linked thread of even a single successful compromise actually occurring, or malicious code making it into legitimate upstream projects.
- ache7 4y agoHere is a commit with malicious code from a Microsoft employee: https://github.com/promonlogicalis/asn1/commit/7bdca06d0edf895069dc25fb60a49c6dae27b916 https://github.com/promonlogicalis/asn1/commit/7bdca06d0edf8...
- raggi 4y agoThat commit was rewritten from https://github.com/Logicalis/asn1/commit/d60463189a563e49f196e0c3fb0acba2c4730a04 https://github.com/Logicalis/asn1/commit/d60463189a563e49f19... which was signed, but is not in the fork.
- ache7 4y agoDamn, github should show some big visible warning about this.
- vladvasiliu 4y agoThis is interesting. If you go to that user's profile, and look at the "contributions", there are none in July / August. Yet the commit is from two days ago.
- 3np 4y agoAs long as the commit is not signed (marked green), that means nothing.
- soruly 4y agonote that it's 35,613 code results, not 35k repos and 13K of the search results come from this org https://github.com/redhat-operator-ecosystem https://github.com/redhat-operator-ecosystem
- Karellen 4y agohttps://twitter.com/stephenlacy/status/1554718086657282049 https://twitter.com/stephenlacy/status/1554718086657282049
- oefrha 4y agoAnd these aren't compromised projects, they are repos created by the "attacker" if you can even call them that. Of course anyone can push malware to their own account. The author admits this in the thread: > The attacker creates FAKE orgs/repos and pushes clones of LEGIT projects to github. Pure scaremongering and/or attention seeking. Edit: Sorry, I posted two similar comments because my first top level one was immediately downvoted to the bottom. It has since come back up.
- oefrha 4y agoWhat a garbage clickbait thread. From scary words like "attack", "infected", etc. you would think projects are compromised. But nothing is compromised. From wayyyyy down in the thread: > The attacker creates FAKE orgs/repos and pushes clones of LEGIT projects to github. Yeah, anyone can push anything to their own GitHub accounts/orgs, including malware. We know that. Save yourself some time. Flagged.
- yorwba 4y agohttps://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html > If you flag, please don't also comment that you did.
- NuclearFishin 4y agoThe risk here is that somebody might download the fake repo mistaking it for the real one
- gary_0 4y agoEspecially considering how easy it is for duplicate content to reach the top results on Google these days.
- raggi 4y agoFrom what I can see, he wrote the tweet after organically finding one of these via Google and then searching and finding that there were many many more. It's absolutely true that the wording is wrong, but I think it's reasonable to accept a jumped the gun rather than a clickbait explanation. The presence of large volumes of project copies on typosquats and synonym squats is still a problem, they'll still get indexed by tools, and then the tools boost their page rank, and eventually some make it to users. Given that the Go init payload contains an RCE and not just a data collection, there is still something of note there. Yes it's not 35k compromised projects, but it is a broad deployment of malicious code.
- gnomewascool 4y agoYes, the scope is not "35k existing GitHub repos are infected", since AFAICT all the infected repos are forks, so the title is misleading. However: 1. The scale is pretty worrying. Given the total number of repos on GitHub (> 100M) it's a drop in the ocean, but still huge. 2. Typo-squatting on, say, PyPI or npmjs is certainly note-worthy, and this is a very similar attack. 3. At least some of the infected forks had several stars, some from ~ 5 year old accounts, so apparently some people were using them. 4. The original Twitter thread did note that infected forks were being created — it just didn't emphasise that this was the only attack surface, probably because the author didn't realise.
- rollulus 4y agoWhile browsing the nanobox repo linked in the twitter thread I started to get 404s, so it looks like GitHub is on it. Edit: other repos have vanished as well now.
- abctree 4y agoThis is a consequence of centralization. The canonical project sites and repositories should not be on GitHub. Fanatics who believe otherwise will still clone those projects so that they are on sacred ground, but the practice should be frowned upon and fought against. Another detrimental effect of GitHub is that they have trained users to accept public "forks" (a misnomer) as the usual way to contribute even trivial patches. This lowers the bar for accepting and trusting non-official repositories. GitHub has devalued the brand of large projects and has introduced the age of industrialized software development by creating an addictive environment where software politicians thrive by manipulating their social networks and working on their personal brand.
- mudrockbestgirl 4y agoI'm upvoting just for the hot take.
- thih9 4y ago> Correction, 35k+ "code hits" on github, not infected repositories. Source: https://mobile.twitter.com/stephenlacy/status/1554718086657282049 https://mobile.twitter.com/stephenlacy/status/15547180866572...
- dustinmoris 4y agoDo we need verified orgs on GitHub now?