3 ms·
Anyone done reverse engineering on what the dll does? The advice of rolling back versions wouldn't be sufficient if it also exfiltrated ssh keys and such for pu
by _lvbh 1y ago
Anyone done reverse engineering on what the dll does? The advice of rolling back versions wouldn't be sufficient if it also exfiltrated ssh keys and such for pushing to git
- warmedcookie 1y agoI was infected and it disables chrome security flags (you'll see a banner in Chrome indicating this) and probably a bunch of other nasty things. I unplugged my Ethernet, turned off the computer, bought a new SSD and installed fresh copy of windows on it. Deleted the boot files / renamed windows folder on infected SSD and slowly pull files over that I need. I also deleted all SSH keys / changed passwords. Lessons learned? Disable scripts and run in a container. Bright side? I now have a 4TB SSD instead of a 2TB SSD.
- nateb2022 1y agoFor what it's worth, both bun and deno disable lifecycle scripts by default (bun has a default allowlist of the top 500 npm packages with lifecycle scripts, however none of the affected packages are on that list: https://github.com/oven-sh/bun/blob/main/src/install/default-trusted-dependencies.txt https://github.com/oven-sh/bun/blob/main/src/install/default...). Switching to a secure-by-default package manager, I think, is something this type of event should make us all reconsider.