Github scam investigation: Thousands of “mods” and “cracks” stealing data
1–10 of 165 posts
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#2Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#3Most fun you can have is to generate real-like looking data (there are tools for that) and mass send them to these discord webhooks.
;-)
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#4Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#5Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
Maybe? But definitely to less people? I don't see the argument for allowing them.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#6Ooh, these types of malwares are very old. Most fun you can have is to generate real-like looking data (there are tools for that) and mass send them to these discord webhooks. ;-)
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#7Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#8Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
Doesn't distributing malware break a number of laws?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#9Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
Doesn't distributing malware break a number of laws?
personally if i post such things i will either ensure it has detections everywhere or somehow neuter it. usually for research you dont really need to have fully functioning malware. just enough to prove some question. so despite posting sources of malware being ok, and it being available in lots of places, i do think, especially for advanced things, its better not to contribute it freely... but to each their own. i'd advise strongly against just outright posting functional cyber weapons, not because its illegal, but simply because its really not needed. there is more bad potential than positive use compared to broken or incomplete versions.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#10Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
So, sounds like the Github team should take some action here.