5 ms·
This account was spamming Python repositories with the same type of low value obvious backdoor spam.[1] Full list of attempted pull requests (all deleted seemi
by dhx 2y ago
This account was spamming Python repositories with the same type of low value obvious backdoor spam.[1]
Full list of attempted pull requests (all deleted seemingly by GitHub):
1 https://www.github.com/KurtBestor/Hitomi-Downloader/pull/7638
2 https://www.github.com/home-assistant/core/pull/130423
3 https://www.github.com/celery/celery/pull/9407
4 https://www.github.com/chriskiehl/Gooey/pull/921
5 https://www.github.com/crewAIInc/crewAI/pull/1582
6 https://www.github.com/cumulo-autumn/StreamDiffusion/pull/177
7 https://www.github.com/AUTOMATIC1111/stable-diffusion-webui/pull/16646
8 https://www.github.com/Aider-AI/aider/pull/2343
9 https://www.github.com/aboul3la/Sublist3r/pull/383
10 https://www.github.com/plotly/dash/pull/3073
11 https://www.github.com/soimort/you-get/pull/3034
12 https://www.github.com/streamlink/streamlink/pull/6290
13 https://www.github.com/jumpserver/jumpserver/pull/14440
14 https://www.github.com/junyanz/pytorch-CycleGAN-and-pix2pix/pull/1684
15 https://www.github.com/kornia/kornia/pull/3069
16 https://www.github.com/langflow-ai/langflow/pull/4520
17 https://www.github.com/exo-explore/exo/pull/432
18 https://www.github.com/PostHog/posthog/pull/26144
19 https://www.github.com/PrefectHQ/prefect/pull/15987
20 https://www.github.com/pydantic/pydantic/pull/10822
21 https://www.github.com/pyg-team/pytorch_geometric/pull/9777
22 https://www.github.com/qutebrowser/qutebrowser/pull/8379
23 https://www.github.com/tornadoweb/tornado/pull/3441
24 https://www.github.com/ungoogled-software/ungoogled-chromium/pull/3092
25 https://www.github.com/locustio/locust/pull/2980
26 https://www.github.com/matterport/Mask_RCNN/pull/3057
27 https://www.github.com/Stability-AI/generative-models/pull/425
28 https://www.github.com/yt-dlp/yt-dlp/pull/11520
[1] https://play.clickhouse.com/play?user=play#U0VMRUNUICogRlJPTSBnaXRodWJfZXZlbnRzIFdIRVJFIGFjdG9yX2xvZ2luID0gJ2V2aWxkb2pvNjY2Jw== https://play.clickhouse.com/play?user=play#U0VMRUNUICogRlJPT...
- dilyevsky 2y agoUniversity of Minnesota at it again?
- ziddoap 2y agoFor those who don't get the reference, there was an incident where security research by University of Minnesota students/professors was conducted without communicating or receiving permission from anyone on the Linux side or from the Institutional Review Board (IRB). It raised a lot of questions about conducting ethical security research on open source projects, whether security research of this nature counts as an "experiment on people" (which has a lot more scrutiny, obviously), etc. "[...] Lu and Wu explained that they’d been able to introduce vulnerabilities into the Linux kernel by submitting patches that appeared to fix real bugs but also introduced serious problems." https://cse.umn.edu/cs/linux-incident https://cse.umn.edu/cs/linux-incident https://www.theverge.com/2021/4/30/22410164/linux-kernel-university-of-minnesota-banned-open-source https://www.theverge.com/2021/4/30/22410164/linux-kernel-uni...
- stratom 2y agoYes, really looks like someone conducting a study, or someone who wants to call out projects for their sloppy PR reviews.
- thebears5454 2y agoI think it looks like someone just ham fisting a known vulnerability trying to find one sucker who doesn't know what he's doing. If you're a jr with a learning projects maybe you'd approve the merge.
- snvzz 2y agoCan't help but wonder... did anyone bite?
- guappa 2y agoI moved to codeberg and there's nothing of the sort going on there. Quite relaxing. On github I did get weird and suspicious contributions.