Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mgii
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
3 ms
·
1.
▲
by
mgii
3y ago
Notice that as it seems, the vast majority are caught and deleted due to the intense automation, not the detection of malicious contents. If the actor was to run a smoother automation process, probably nothing would have been deleted. (disc
2.
▲
by
mgii
3y ago
To be fair, the kind of programmer who would include an infected repo is almost everyone. Many infected repos have no indicators except for username to help you notice without a careful examination, especially in niche repos. When you have
3.
▲
by
mgii
3y ago
I can approve this from our findings (author of this research): our system lists around 100 instances of the pattern you've mentioned every week, and around %3 are malicious. It would be great seeing it coming to an end.
4.
▲
by
mgii
3y ago
This is more likely than one would think, given such a large amount of samples as detected in this campaign. But there are at least 2 main barriers of an actual incident: 1. Internal instructions telling the generator to avoid exactly that.
5.
▲
by
mgii
3y ago
There seems to be a lot of confusion between malware and vulnerabilities. None of the vendors mentioned in this subthread detects malicious code, only vulnerabilities. Good as they'll be in detecting vulnerabilities, you are still unpr
6.
▲
Over 100k infected repos found on GitHub
(apiiro.com)
1 points
by
mgii
3y ago
|
2 comments