3 ms·
> How is this a supply chain attack? It's a supply-chain attack because the article has a section about how the official website for "Free Download Manager" wa
by dotty- 3y ago
> How is this a supply chain attack?
It's a supply-chain attack because the article has a section about how the official website for "Free Download Manager" was serving malware to a percentage of people.
> While checking videos on Free Download Manager that are hosted on YouTube, we identified several tutorials demonstrating how to install this software on Linux machines. We observed the following actions that happen in all these videos:
> - The video makers opened the legitimate website of Free Download Manager (freedownloadmanager[.]org) in the browser;
> - They afterwards clicked on the Download button for the Linux version of the software;
> - They were redirected to the malicious https://deb.fdmpkg[.]org/freedownloadmanager.deb https://deb.fdmpkg[.]org/freedownloadmanager.deb URL that hosts the infected version of Free Download Manager.
- deleted 3y ago[deleted]
- Nursie 3y agoIt's a supply-chain attack on Free Download Manager, rather than on linux itself. The truncated HN headline makes this seem like it's a general linux problem.