4 ms·
How would code like this make it into so many repos? People accepting pull requests and not properly reviewing them? Or is there something even worse about th
by muppetman 4y ago
How would code like this make it into so many repos? People accepting pull requests and not properly reviewing them? Or is there something even worse about this attack?
- pcmonk 4y agoMost of them don't seem to come from pull requests, I wonder if it's paired with a bunch of compromised github accounts?
- bonzini 4y agoNot compromised, just created by the attacker.
- deleted 4y ago[deleted]
- stevelacy 4y agoMany of the repos I found were clones of valid projects with same names under new orgs and new users. For instance, this projects is valid: https://github.com/scala-network/GUI-miner https://github.com/scala-network/GUI-miner and it's infected clone: https://github.com/stellitecoin/gui-miner https://github.com/stellitecoin/gui-miner GPG signed commits by the legitimate users do not contain the malware
- laserlight 4y agoConsidering that only clones are affected, your original tweet is downright wrong. None of the listed projects (python, js, bash, docker, k8s) are affected. Anybody can fork a repository to introduce malware.
- eurasiantiger 4y agojs is a project?
- laserlight 4y agoYou're right. It's not. I just copy-pasted the list from the tweet. I assume that the author meant to write jq.