4 ms·
Out of curiosity I looked at the list of followers of the account who committed the backdoor. Randomly picked https://github.com/Neustradamus https://github.co
by 0xthr0w4 3y ago
Out of curiosity I looked at the list of followers of the account who committed the backdoor.
Randomly picked https://github.com/Neustradamus https://github.com/Neustradamus and looked at all their contributions.
Interestingly enough, they got Microsoft to upgrade ([0],[1]) `vcpkg` to liblzma 5.6.0 3 weeks ago.
[0] https://github.com/microsoft/vcpkg/issues/37197 https://github.com/microsoft/vcpkg/issues/37197
[1] https://github.com/microsoft/vcpkg/pull/37199 https://github.com/microsoft/vcpkg/pull/37199
- sroussey 3y agoOMG: look at the other contributions. He is trying to take over projects and pushing some change to sha256 in a hundred projects. Example: https://github.com/duesee/imap-flow/issues/96 https://github.com/duesee/imap-flow/issues/96
- masklinn 3y agoThis guy's interactions seem weird but it might just be because of the non-native english or a strange attitude, or he's very good at covering his track e.g. found a cpython issue where he got reprimanded for serially opening issues: https://github.com/python/cpython/issues/115195#issuecomment-1935707908 https://github.com/python/cpython/issues/115195#issuecomment... But clicking around he seems to mostly be interacting with interest around these bits e.g. https://github.com/python/cpython/issues/95341#issuecomment-1802889364 https://github.com/python/cpython/issues/95341#issuecomment-... or pinging the entire python team to link to the PR... of a core python developer: https://github.com/python/cpython/issues/95341#issuecomment-1872618454 https://github.com/python/cpython/issues/95341#issuecomment-... If I saw that on a $dayjob project I'd pit him as an innocuous pain in the ass (overly excited, noisy, dickriding). Here's a PR from 2020 where he recommends / requests the addition of SCRAM to an SMTP client: https://github.com/marlam/msmtp/issues/36 https://github.com/marlam/msmtp/issues/36 which is basically the same thing as the PR you found. The linked documents seem genuine, and SCRAM is an actual challenge/response authentication method for a variety of protocols (in this case mostly SMTP, IMAP, and XMPP): https://en.wikipedia.org/wiki/Salted_Challenge_Response_Authentication_Mechanism https://en.wikipedia.org/wiki/Salted_Challenge_Response_Auth... Although, and that's a bit creepy, he shows up in the edition history for the SCRAM page, the edit mostly seem innocent though he does plug his "state of play" github repository.
- robocat 3y ago> dickriding https://www.urbandictionary.com/define.php?term=Dickriding https://www.urbandictionary.com/define.php?term=Dickriding I guess I'm not in the right demographic to know the term.
- JdeBP 3y ago"fawning" or "ingratiating" seem to be the standard English words for this.
- sroussey 3y agoTrue, it does seem innocent enough upon more reflection.
- gowthamgts12 3y agoreported the account to github, just in case.
- arp242 3y agoWhat? They're just asking for some features there? Ya'll need to calm down; this is getting silly. Half the GitHub accounts look "suspicious" if you start scrutinizing everything down the the microscopic detail.
- deleted 3y ago[deleted]
- gaucheries 3y agoI appreciate the way that duesee handled that whole issue.
- deleted 3y ago[deleted]
- _cenw 3y agoHey, I remember this guy! Buddy of someone who tried to get a bunch of low quality stuff into ifupdown-ng, including copying code with an incompatible license and removing the notice. He's in every PR, complaining the "project is dead". He even pushes for the account to be made "team member". https://github.com/ifupdown-ng/ifupdown-ng/pulls/easynetdev https://github.com/ifupdown-ng/ifupdown-ng/pulls/easynetdev He follows 54k accounts though, so it may indeed just be coincidence.
- dikei 3y agoI wouldn't be surprised if that is just a bot. He even follows me, though I have never published any open-source project on my own.
- account42 3y agoThe PR + angry user pushing for the PR author to gain commit access spiel is definitely suspiciously similar to what happened with xz-utils. Possible coincidence but worth investigating further.
- neustradamus 3y agoDear @0xthr0w4, do you attack me because I have requested the XZ update? Do not mix, I am not linked to the XZ project.
- resonious 3y agoThe parent comment doesn't read like an attack to me. Just an observation. Would be curious why you wanted the update though.