10 ms·
Shai-Hulud compromised a dev machine and raided GitHub org access: a post-mortem
- moh_quz 10mo agoReally appreciate the transparency here. Post-mortems like this are vital for the industry. I'm curious was the exfiltration traffic distinguishable from normal developer traffic? We've been looking into stricter egress filtering for our dev environments, but it's always a battle between security and breaking npm install
- robinhoodexe 10mo agoWouldn’t the IP allowlist feature on the GitHub organisation work wonders for this kind of attack?
- moh_quz 10mo agoThat definitely helps, but I don't think it solves the compromised machine scenario. If the attacker has shell access to the dev's laptop, they are likely just running commands directly from that machine (or proxying through it). So to GitHub, the traffic still looks like it's coming from the allowed IP. Allowlists are mostly for stopping usage of a token that got stolen and taken off-device.
- zozos 10mo agoI have been thinking about this. How do I make my git setup on my laptop secure? Currently, I have my ssh key on the laptop, so if I want to push, I just use git push. And I have admin credentials for the org. How do I make it more secure?
- noman-land 10mo agoYou can add a gpg key and subkeys to a yubikey and use gpg-agent instead of ssh-agent for ssh auth. When you commit or push, it asks you for a pin for the yubikey to unlock it.
- esseph 10mo agoYou can put the ssh privkey on the yubikey itself and protect it with a pin. You can also just generate new ssh keys and protect them with a pin.
- larusso 10mo ago1 store my ssh key in 1Password and use the 1Password ssh agent. This agents asks for access to the key(s) with Touch ID. Either for each access or for each session etc. one can also whitelist programs but I think this all reduces the security.
- larusso 10mo agoThere is the FIDO feature which means you don’t need to hackle with gpg at all. You can even use an ssh key as signing key to add another layer of security on the GitHub side by only allowing signed commits.
- benoau 10mo agoYou can set up your repo to disable pushing directly to branches like main and require MFA to use the org admin account, so something malicious would need to push to a benign branch and separately be merged into one that deploys come from.
- sallveburrpi 10mo agoPushing directly to main seems crazy - for anything that is remotely important I would use a pull request/merge request pattern
- esseph 10mo agoDepends on the use case of the repo.
- otterley 10mo agoThere's nothing wrong with pushing to main, as long as you don't blindly treat the head of the main branch as production-ready. It's a branch like any other; Git doesn't care what its name is.
- sallveburrpi 10mo agoYea ofc I was implying that main is the branch that is pushed to production.
- t0mas88 10mo agoBut the attacker could just create a branch, merge request and then merge that?
- CGamesPlay 10mo agoAdd a password or hardware 2-factor to your ssh key. And get a password manager with the same for those admin credentials.
- madeofpalk 10mo agoI’ve started to get more and more paranoid about this. It’s tough when you’re running untrusted code, but I think I’ve improved this by: not storing SSH keys on the filesystem, and instead using an agent (like 1Password) to mediate access Stop storing dev secrets/credentials on the filesystem, injecting them into processes with env vars or other mechanisms. Your password manager could have a way to do this. Develop in a VM separate from your regular computer usage. On windows this is essential anyway through using WSL, but similar things exist for other OSs
- anthonyryan1 10mo agoOne approach I started using a could of years ago was storing SSH private keys in the TPM, and using it via PKCS11 in SSH agent. One benefit of Microsoft requiring them for Windows 11 support is that nearly every recent computer has a TPM, either hardware or emulated by the CPU firmware. It guarantees that the private key can never be exfiltrated or copied. But it doesn't stop malicious software on your machine from doing bad things from your machine. So I'm not certain how much protection it really offers on this scenario. Linux example: https://wiki.gentoo.org/wiki/Trusted_Platform_Module/SSH https://wiki.gentoo.org/wiki/Trusted_Platform_Module/SSH macOS example (I haven't tested personally): https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb4acf https://gist.github.com/arianvp/5f59f1783e3eaf1a2d4cd8e952bb...
- homebrewer 10mo agoOr use a FIDO token to protect your SSH key, which becomes useless without the hardware token. https://wiki.archlinux.org/title/SSH_keys#FIDO/U2F https://wiki.archlinux.org/title/SSH_keys#FIDO/U2F That's what I do. For those of us too lazy to read the article, tl;dr: ssh-keygen -t ed25519-sk or, if your FIDO token doesn't support edwards curves: ssh-keygen -t ecdsa-sk tap the token when ssh asks for it, done. Use the ssh key as usual. OpenSSH will ask you to tap the token every time you use it: silent git pushes without you confirming it by tapping the token become impossible. Extracting the key from your machine does nothing — it's useless without the hardware token.
- NylonMeltdown 10mo agoExcept that an attacker can modify the ssh config to enable session multiplexing with a long timeout and then piggy-back off that connection, right?
- TacticalCoder 10mo agoAre you saying that because there are still more complicated potential attacks hardware tokens offer zero benefits? Anyway, what about the sshd server having this config line: sshd_config MaxSessions 1 could that help?
- otterley 10mo agoYour SSH private key must be encrypted using a passphrase. Never store your private key in the clear!
- nottorp 10mo agoAnd what do you do with the passphrase, store it encrypted with a passphrase?
- 0xbadcafebee 10mo agoYou memorize it, or keep it in 1Password. 1Password can manage your SSH keys, and 1Password can/does require a password, so it's still protected with something you know + something you have.
- fwip 10mo agoOne option is to remember it.
- nottorp 10mo agoI don’t think that’s considered secure enough, see the other answers and the push for passkeys. I mean, if passphrases were good for anything you’d directly use them for the ssh connection? :)
- otterley 10mo agoPassphrases, when strong enough, are fine when they are not traversing a medium that can be observed by a third party. They're not recommended for authenticating a secure connection over a network, but they’re fine for unlocking a much longer secret that cannot be cracked via guessing, rainbow tables, or other well known means. Hell, most people unlock their phones with a 4 digit passcode, and their computers with a passphrase.
- nottorp 10mo ago> when they are not traversing a medium that can be observed by a third party Isn't that why all those security experts are pushing for SSL everywhere and 30 second certificate expiration? To make the medium unobservable by a third party? If you believe them, passphrases should be okay over fiber you don't control too.
- 0xbadcafebee 10mo ago1) Get 1Password, 2) use 1Password to hold all your SSH keys and authorize SSH access [1], 3) use 1Password to sign your Git commits and set up your remote VCS to validate them [2], 4) use GitHub OAuth [3] or the GitHub CLI's Login with HTTPS [4] to do repository push/pull. If you don't like 1Password, use BitWarden. With this setup there are two different SSH keys, one for access to GitHub, one is a commit signing key, but you don't use either to push/pull to GitHub, you use OAuth (over HTTPS). This combination provides the most security (without hardware tokens) and 1Password and the OAuth apps make it seamless. Do not use a user with admin credentials for day to day tasks, make that a separate user in 1Password. This way if your regular account gets compromised the attacker will not have admin credentials. [1] https://developer.1password.com/docs/ssh/agent/ https://developer.1password.com/docs/ssh/agent/ [2] https://developer.1password.com/docs/ssh/git-commit-signing/ https://developer.1password.com/docs/ssh/git-commit-signing/ [3] https://github.com/hickford/git-credential-oauth https://github.com/hickford/git-credential-oauth [4] https://cli.github.com/manual/gh_auth_login https://cli.github.com/manual/gh_auth_login
- zozos 10mo agoI already use 1password and have it already installed. Will try this out. Thanks!
- throw14082020 10mo agoOkay great advice, thanks. I'm already using Bitwarden and found out they have an SSH Agent feature too [1]. I've tried lastpass, Bitwarden, 1password and I prefer Bitwarden (good UX, very affordable) [1] https://bitwarden.com/help/ssh-agent/ https://bitwarden.com/help/ssh-agent/
- madeofpalk 10mo agoMake sure the gh cli isn’t storing oauth credentials in plaintext as it can silently do.
- DANmode 10mo agoBitwarden verbiage deserves to be higher than 1Password, here.
- snickerbockers 10mo agopassword-protect your key (preferably with a good password that is not the same password you use to log in to your account). If you use a password it's encrypted; otherwise its stored on plaintext and anybody who manages to get a hold of your laptop can steal the private key.
- mr_mitm 10mo agoThere is no defense against a compromised laptop. You should prevent this at all cost. You can make it a bit more challenging for the attacker by using secure enclaves (like TPM or Yubikey), enforce signed commits, etc. but if someone compromised your machine, they can do whatever you can. Enforcing signing off on commits by multiple people is probably your only bet. But if you have admin creds, an attacker can turn that off, too. So depending on your paranoia level and risk appetite, you need a dedicated machine for admin actions.
- otterley 10mo agoIt's more nuanced than that. Modern OSes and applications can, and often do, require re-authentication before proceeding with sensitive actions. I can't just run `sudo` without re-authenticating myself; and my ssh agent will reauthenticate me as well. See, e.g., https://developer.1password.com/docs/ssh/agent/security https://developer.1password.com/docs/ssh/agent/security
- mr_mitm 10mo agoThe malware can wait until you authenticate and perform its actions then in the context of your user session. The malware can also hijack your PATH variable and replace sudo with a wrapper that includes malicious commands. It can also just get lucky and perform a 'git push' while your SSH agent happens to be unlocked. We don't want to rely on luck here. Really, it's pointless. Unless you are signing specific actions from an independent piece of hardware [1], the malware can do what you can do. We can talk about the details all day long, and you can make it a bit harder for autonomously acting malware, but at the end of the day it's just a finger exercise to do what they want to do after they compromised your machine. [1] https://www.reiner-sct.com/en/tan-generators/tan-generator-for-the-sparkasse-via-chiptan-qr/ https://www.reiner-sct.com/en/tan-generators/tan-generator-f... (Note that a display is required so you can see what specific action you are actually signing, in this case it shows amount and recipient bank account number.)
- otterley 10mo agoDo you have evidence or a reproducible test case of a successful malware hijack of an ssh session using a Mac and the 1Password agent, or the sudo replacement you suggested? I assume you fully read the link I sent? I don't think you're necessarily wrong in theory -- but on the other hand you seem to discount taking reasonable (if imperfect) precautionary and defensive measures in favor of an "impossible, therefore don't bother" attitude. Taken to its logical extreme, people with such attitudes would never take risks like driving, or let their children out of the house.
- benfrancom 10mo agoIf github, take a look at gh cli or git credential manager: https://docs.github.com/en/get-started/git-basics/caching-your-github-credentials-in-git https://docs.github.com/en/get-started/git-basics/caching-yo...
- progbits 10mo agoI wouldn't say that's better. Now your .config directory contains a github token that can do more than just repo pull/push, and it is trivially exfiltrated. Though similar thing could be said for browser cookies.
- mshroyer 10mo agoNot a perfect defense, but sufficient to make your key much harder to exploit: Use a Yubikey (or similar) resident SSH key, with the Yubikey configured to require a touch for each authentication request.
- TacticalCoder 10mo ago> Currently, I have my ssh key on the laptop ... My SSH keys aren't on my computer: they're safely hidden on a hardware token, behind a secure element, like a Yubikey. Devices like the Yubikey do precisely exist because computers aren't things to be trusted. So their reason for being is to offer a minimal attack surface. When I git fetch/pull/push I just do it. But it requires me to physically use my Yubikey. It's not 100% foolproof but it's way better than having SSH keys only protected by a password. So Git over SSH, on a Git/SSH server that supports Yubikeys.
- fsflover 10mo agoYou can use split-ssh on Qubes OS, such that your development environment won't have the access to your private keys: https://forum.qubes-os.org/t/split-ssh/19060 https://forum.qubes-os.org/t/split-ssh/19060
- getnormality 10mo agoI am loving the ancient Lovecraftian horror vibe of these exploit names. Good for raising awareness, I guess!
- dnpls 10mo agoAFAIK Shai-Hulud is the sandworm in Frank Herbert's Dune (but also an American metalcore band)
- snickerbockers 10mo agoShai Hulud is the god that lives inside the sandworms in Dune.
- getnormality 10mo agoNoted!
- Etheryte 10mo agoThe approach the attacker took makes little sense to me, perhaps someone else has an explanation for it? At first they monitored what's going on and then silently exfiltrated credentials and private repos. Makes sense so far. But then why make so much noise with trying to force push repositories? It's Git, surely there's a clone of nearly everything on most dev machines etc.
- deleted 10mo ago[deleted]
- chuckadams 10mo agoMalware sometimes suffers from feature creep too.
- yokto 10mo agoIt's most likely two or more separate attackers operating. The first malware, Shai Hulud 2, exfiltrates credentials from the infected dev machine to new public GitHub repositories. As the repositories are public and searchable via GitHub's interfaces, any malicious attacker aware of the attack can easily grab the credentials and launch any attack, whether it's a noisy destructive script or some sophisticated ransomware.
- sync 10mo agoThat’s weird, pnpm no longer automatically runs lifecycle scripts like preinstall [1], so unless they were running a very old version of pnpm, shouldn’t they have been protected from Shai-Hulud? 1: https://github.com/pnpm/pnpm/pull/8897 https://github.com/pnpm/pnpm/pull/8897
- e40 10mo agoYeah, I thought that was the main reason to use pnpm. Very confused.
- pverheggen 10mo agoMaybe the project itself had a postinstall script? It doesn't run lifecycle scripts of dependencies, but it still runs project-level ones.
- ItsHarper 10mo agoAt the end of the article, they talk about how they've since updated to the latest major version of pnpm, which is the one with that change
- agilob 10mo agoLet me understand it fully. That means they updated dependencies using old, out of date package manager. If pnpm was up to date, this would no have happened? Sounds totally like their fault then
- debarshri 10mo ago> This incident involved one of our engineers installing a compromised package on their development machine, which led to credential theft and unauthorized access to our GitHub organization. The org only has 4-5 engineers. So you can imagine the impact a large org will have.
- deleted 10mo ago[deleted]
- rvz 10mo agoNPM post-install scripts considered harmful. There has to be a tool that allows you (or an AI) to easily review post-install scripts before you install the package.
- madeofpalk 10mo agoAs mentioned in the article, good NPM package managers just do this now. pnpm does it by default, yarn can be configured. Not sure about npm itself.
- chuckadams 10mo agoGot any pointers on how to configure this for yarn? I'm not turning anything up in the yarn documentation or in my random google searches. npm still seems to be debating whether they even want to do it. One of many reasons I ditched npm for yarn years ago (though the initial impetus was npm's confused and constantly changing behaviors around peer dependencies)
- baobun 10mo agoYarn is unfortunately a dead-end security-wise under current maintainership. If you are still on yarn v1 I suggest being consistent with '--ignore-scripts --frozen-lockfile' and run any necessary lifecycle scripts for dependencies yourself. There is @lavamoat/allow-scripts to manage this if your project warrants it. If you are on newer yarn versions I strongly encourage to migrate off to either pnpm or npm.
- jrochkind1 10mo agonewer yarn versions are _less_ secure than the ancient/abandoned yarn 1? :( Any links for further reading on security problems "under current maintainership"?
- madeofpalk 10mo agoenableScripts: false in .yarnrc.yml https://yarnpkg.com/configuration/yarnrc#enableScripts https://yarnpkg.com/configuration/yarnrc#enableScripts And then opt certain packages back in with dependenciesMeta in package.json https://yarnpkg.com/configuration/manifest#dependenciesMeta.built https://yarnpkg.com/configuration/manifest#dependenciesMeta....
- skrebbel 10mo agoPoints for an excellent post-mortem.
- KomoD 10mo ago> stored in our database which was not compromised Personally I don't really agree with "was not compromised" You say yourself that the guy had access to your secrets and AWS, I'd definitely consider that compromised even if the guy (to your knowledge) didn't read anything from the database. Assume breach if access was possible.
- nsonha 10mo agoThere are logs for accessing aws resources and if you don't see the access before you revoke it then the data is safe
- MrDarcy 10mo agoUnless the attacker used any one of hundreds of other avenues to access the AWS resource. Are you sure they didn’t get a service account token from some other service then use that to access customer data? I’ve never seen anyone claim in writing all permutations are exhaustively checked in the audit logs.
- otterley 10mo agoIt depends on what kind of access we're talking about. If we're talking about AWS resource mutations, one can trust CloudTrail to accurately log those actions. CloudTrail can also log data plane events, though you have to turn it on, and it costs extra. Similarly, RDS access logging is pretty trustworthy, though functionality varies by engine.
- MrDarcy 10mo agoWhat do you mean by “trust cloud trail” So cloud trail shows the compromised account logging into an EC2 instance every day like normal. Then service account credentials are used to access user data in S3. How does cloud trail indicate the compromised credentials were used to access the customer data in S3?
- 10mo ago
- bspammer 10mo agoGiven that all the stolen credentials were made public, I was hoping that someone would build a haveibeenpwned style site. We know we were compromised on at least a few tokens, but it would be nice to be able to search using a compromised token to find out what else leaked. We’ve rotated everything we could think of but not knowing if we’ve missed something sucks.
- KomoD 10mo agoDoesn't it publish the repos to your Github account? Just clone and look at what was stolen.
- solrith 10mo agoOn the follow up Wiz blog they suggested that the exfiltration was cross-victim https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-supply-chain-attack#leaked-secrets-29 https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-sup...
- bspammer 10mo agoAs the sibling comment said, the worm used stolen GitHub credentials from other victims, and randomly distributed the uploads between victims. Also everything was double base64 encoded which makes it impossible to use GitHub search.
- ramimac 10mo agoReach out if you'd like me to check - I did the same for the trigger.dev team in fact[1]. (personal site linked in bio, who links you onward to my linkedin) [1] https://x.com/ramimacisabird/status/1994598075520749640?s=20 https://x.com/ramimacisabird/status/1994598075520749640?s=20
- solrith 10mo agoThe Torvalds commits were a common post infection signature, common in the random repos that published secrets (Microsoft documented https://www.microsoft.com/en-us/security/blog/2025/12/09/shai-hulud-2-0-guidance-for-detecting-investigating-and-defending-against-the-supply-chain-attack/ https://www.microsoft.com/en-us/security/blog/2025/12/09/sha...) It was a really noisy worm though, and it looked like a few actors also jumped on the exposed credentials making private repos public and modifying readmes promoting a startup/discord.
- snickerbockers 10mo ago>Running npm install is not negligence. Installing dependencies is not a security failure. The security failure is in an ecosystem that allows packages to run arbitrary code silently. No, your security failure is that you use a package manager that allows third-parties push arbitrary code into your product with no oversight. You only have "secutity" to the extent that you can trust the people who control those packages to act both competently and in good faith ad infinitum. Also the OP seemingly implies credentials are stored on-filesystem in plaintext but I might be extrapolating too much there.
- deepsun 10mo agoSame thing with IDE plugins. At least some are full-featured by the manufacturer, but I couldn't get on with VS Code as for every small feature I had to install some random plugin (even if popular, but still developed by who-knows-who).
- willvarfar 10mo agoThe amount of browser extension authors who have talked openly about being approached to sell their extension or insert malicious code is many, and presumably many others have taken the money and not told us about it. It seems likely there are IDE extensions doing or going to do the same thing...
- packtreefly 10mo agoIt's painful, but I've grown distrustful enough of the ecosystem that I disable updates on every IDE plugin not maintained by a company with known-adequate security controls and review the source code of plugin changes before installing updates, typically opting out unless something is broken. It's unclear to me if the code linked on the plugin's description page is in amy way guaranteed to be the code that the IDE downloads. The status quo in software distribution is simultaneously convenient, extraordinarily useful, and inescapably fucked.
- elif 10mo agoIt wasn't in their product. It was just on a devs machine
- Rafert 10mo ago> This is one of the frustrating realities of these attacks: once the malware runs, identifying the source becomes extremely difficult. The package doesn't announce itself. The pnpm install completes successfully. Everything looks normal. Sounds like there’s no EDR running on the dev machines? You should have more to investigate if Sentinel One/CrowdStrike/etc were running.
- sciencejerk 10mo agoYep. I think EDR would have detected, alerted if not completely killed a noisy Trufflehog attack chain
- h1fra 10mo agoWe don't have a clear explanation of the destructive behavior, right? It looks like it had no real purpose, and there were much more effective ways of destroying their repos. Very script kiddie-like, which does not really fit the main complexity of the virus. Very surprising.
- n2d4 10mo agoIt hides the malware's trail, and disguises which keys were leaked, making rotation harder
- ack_inc 10mo agoThe socket.dev deconstruction of the worm (https://socket.dev/blog/shai-hulud-strikes-again-v2 https://socket.dev/blog/shai-hulud-strikes-again-v2) suggests that the destructive actions on GitHub were not part of the malware itself.
- progbits 10mo agoVery offtopic but this caught my eye: > Total repos cloned: 669 How big is this company? All the numbers I can find online suggest well below 100 people, and yet they have over 600 repos? Is that normal?
- rsyring 10mo agoMy org is currently at 7 people and we have 365 repositories associated with our github org. We've been around for a number of years and I'd guess that impacts the number of repos more than the number of team members.
- LtWorf 10mo agoIf they have an architect that loves microservices and thinks every microservice needs its own repo that's what happens (insanity).
- lmm 10mo agoCompletely normal yes. Repos are cattle not pets.
- voidnap 10mo ago> Repos are cattle not pets. What do you mean by this?
- arkits 10mo agoYou can have more than a few
- a_vanderbilt 10mo agoA core SRE principle is that "machines/servers are cattle, not pets". They shouldn't be special or bespoke in a way that makes replacement painful or difficult.
- voidnap 10mo agoI've heard the term used for servers before but not version control repositories. I just don't understand what it would mean for a git repo to be a cattle vs a pet. Like what is an example of a cattle repo vs a pet repo. The metaphore just sounds like gibberish to me idk. Unless all it means is that that you can have more than a few like the other commenter said but I didn't think that was what the metaphore meant with respect to servers so again I have no idea lol
- Yasuraka 10mo ago> Running npm install is not negligence. I beg to differ and look forward to running my own fiefdom where interpreter/JIT languages are banned in all forms.
- staticassertion 10mo agoIt has nothing to do with interpreters or JIT, it has nothing to do with npm at all. All package managers have the insane security model of "arbitrary code execution with no constraints".
- seniorsassycat 10mo agoI tend to agree but think npms post install hook is a degree worse. Triggering during install, silently because npm didn't like someone using the feature to ask for donations, is worse than requiring you to load and run the package code.
- staticassertion 10mo agoWhich package managers don't contain an equivalent feature for running code as part of the install process?
- Yasuraka 10mo agoIt just so happens that all of those languages share the worst design points, such as the need for a package manager at all and the classic "eval and equivalents run arbitrary code". >All package managers have the insane security model of "arbitrary code execution with no constraints". Not all of them, just the most popular ones for these highly sophisticated, well thought-out bunch of absolute languages.
- staticassertion 10mo agoWhat language does not have a popular package manager that provides code execution?
- marifjeren 10mo ago> """ I'm strongly in favor of blocking post-install scripts by default. :+1: This is a change that will have a painful adjustment period for our users, but I believe in ~1 year everyone will look back and be thankful we made it. It's nuts that a [pnpm|yarn|npm] install can run arbitrary code in the first place. """ - a pnpm maintainer 1 year ago https://github.com/pnpm/pnpm/pull/8897 https://github.com/pnpm/pnpm/pull/8897
- classified 10mo agoAnd yet here we are… Convenience trumps security every time. With people who allegedly know better.
- M4v3R 10mo agoWell pnpm does it by default for quite some time. It’s annoying, yes, but I take a little annoyance if it means I’m more secure.
- emmelaich 10mo agoSurprised that people allow force-push on git. If it needs to be done, it should only be done after consultation and disabled after.
- throw14082020 10mo agoIt was on development branches. The threat actor was trying to delete development work. Their main branch was already protected. I don't think it makes sense to protect every single branch in a repo? Since not all devs will have the ability to turn this off
- rurban 10mo ago[dead]
- tylerchilds 10mo agoIt’s almost like Microsoft sells security products and runs the most insecure JavaScript package manager to build those security products and couldn’t switch off of it even if the engineers in the org recommended a more secure JavaScript execution context— and that’s realistically why anthropic bought an engine.
- yashafromrussia 10mo agoI'm wondering why storing creds in env variables as plain text is acceptable - e.g. they better be dynamically fetched from a secret manager with 2FA in the way
- jwrallie 10mo agoWould they detect this if the attackers just silently keep leaking the information, as opposed to go destructive about it?
- ack_inc 10mo ago"The simultaneous activity from US and India confirmed we were dealing with a single attacker using multiple VPNs or servers, not separate actors." Did it really? It's not clear to me why the possibility that the exfiltrated credentials were shared with other actors, each acting independently, is ruled out.
- neoinkarasuyuu 10mo agoYeah, that claim makes no sense by itself, and I found it contradictory as one actor accessing repos over two vpns at the same time seems unlikely. I think if you look at all the actions, and see that they don't overlap, then it might make sense. If access was: Location: Repo USA: 1,2,3,4 India: 5,6,7,8 The it is reasonable to assume that the access was from that same actor, as it is coordinated in some way.
- deleted 10mo ago[deleted]