Live data from Hacker News

Github scam investigation: Thousands of “mods” and “cracks” stealing data

timsh.org

31–40 of 165 posts

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#31
post #29

In my opinion, Microsoft’s entire support is at a tragically poor and hopeless level. GitHub is flooded with open issues that remain open for years without any response from Microsoft. The same applies to Azure. The technical support there is also truly terrible, and it’s easy to find horror stories online about people losing access to their accounts and being unable to restore them.

When GoodbyeDPI malware was spreading using the similar template (lots of forked repos with password-protected archives), Github abuse team have instantly deleted it upon my request. Mean response time was 10-15 minutes. I also deleted files on the file sharing websites, such as mediafire and mega. My abuse emails followed the clear and understandable email template: your service is hosting malware, here's the link,…

However I remembered reporting the exact "cheats/cracks" from the post as well, and the response time was up to 5 days.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#33
I think the core of problem here is that applications are not isolated on the OS level.

If I download and install a mod for minecraft, it should never have access to anything on my computer, except for the minecraft game files itself. If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files.

Something similar to how android works, were the app has to explicitly ask the user to access their files.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#34
post #25

Fun fact: if you come across one of these discord webhooks you can delete them. Just curl -X DELETE https://discord.com/api/webhooks/ [...]

I'm not familiar with the context here, could you please elaborate? If I understood correctly, any unauthenticated user can delete the webhook? I can currently find hundreds of matches for that on Github, anyone could just go and delete them all?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#35
If you've identified GitHub repositories hosting malware, you can report them directly to GitHub via their Abuse Report page, providing links and any relevant details. GitHub typically removes repositories that violate their Acceptable Use Policy, but response times may vary. If the malware is actively being used for harm, you may also consider reporting it to security organizations or CERT teams.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#38
post #33

I think the core of problem here is that applications are not isolated on the OS level. If I download and install a mod for minecraft, it should never have access to anything on my computer, except for the minecraft game files itself. If I open a spreadsheet in Excel, the excel process should have access only to that file and it's own config files. Something similar to how android works, were the app has to explicitl…

You're describing Qubes, which is great but I found it tedious to use as a daily driver.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#39

If you've identified GitHub repositories hosting malware, you can report them directly to GitHub via their Abuse Report page, providing links and any relevant details. GitHub typically removes repositories that violate their Acceptable Use Policy, but response times may vary. If the malware is actively being used for harm, you may also consider reporting it to security organizations or CERT teams.

> response times may vary

Waiting six months for Github to remove malicious repositories is unacceptable.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#40
post #18
post #17

Earlier quoted context omitted.

I use (redacted).on Microsoft.com tenant which is free of cost to me as a sandbox to learn about office 365 admin stuff. I don't work on it every day but it is nice to have this sandbox. I don't send spam or phishing emails. I don't send emails from this tenant at all to others, only to my own email addresses or to people I know for testing purposes.

Presumably you don't send out emails appearing to come from service@paypal.com saying things like "Reminder: You've still got a money request", with an HTML body that looks exactly like Paypal but contains a fraudulent link and phone number, so you should be fine.

Or, worse, I find that most of these are real links from real paypal.

https://www.fortinet.com/blog/threat-research/phish-free-pay...

Post reply on HN