Live data from Hacker News

Github scam investigation: Thousands of “mods” and “cracks” stealing data

timsh.org

1–10 of 165 posts

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#2
Why should malware repos be deleted?

Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#4
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

Only if they disguise as non malware I guess?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#5
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

> would be distributed some other way if GH removed them

Maybe? But definitely to less people? I don't see the argument for allowing them.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#6
post #3

Ooh, these types of malwares are very old. Most fun you can have is to generate real-like looking data (there are tools for that) and mass send them to these discord webhooks. ;-)

An unscrupulous individual might even send malware.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#7
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

Doesn't distributing malware break a number of laws?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#8
post #7
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

Doesn't distributing malware break a number of laws?

What is the definition of distribution? If I posted a code snippet of malware on github or my personal site for educational purposes, does that count as distribution?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#9
post #7
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

Doesn't distributing malware break a number of laws?

totally depends on where u live. id say 99% of places, u wont. also, research purposes is ok if its obvious. u can download malware in lots of places, sources, so taking them off of github really wont do anything either.

personally if i post such things i will either ensure it has detections everywhere or somehow neuter it. usually for research you dont really need to have fully functioning malware. just enough to prove some question. so despite posting sources of malware being ok, and it being available in lots of places, i do think, especially for advanced things, its better not to contribute it freely... but to each their own. i'd advise strongly against just outright posting functional cyber weapons, not because its illegal, but simply because its really not needed. there is more bad potential than positive use compared to broken or incomplete versions.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#10
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

There is an official policy on this: https://docs.github.com/en/site-policy/acceptable-use-polici...

So, sounds like the Github team should take some action here.

Post reply on HN