[flagged]
Github scam investigation: Thousands of “mods” and “cracks” stealing data
61–70 of 165 posts
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#62Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#63Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?
Yes they are. They are being used as delivery mechanism for malware.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#64Some honeypot scheme or social engeneering against them.
Ideas?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#65[flagged]
Is there such a right hosting, with noscript and basic html?
Drop microsoft github and move there or similar.
But the best is to host yourself.
But careful, you are going against big tech interests, expect their shadow-paid hackers to attack you and any real-life alternative you use.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#66Better to have an attitude that Github is malware and a healthy skepticism of any repo?
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#67If you've identified GitHub repositories hosting malware, you can report them directly to GitHub via their Abuse Report page, providing links and any relevant details. GitHub typically removes repositories that violate their Acceptable Use Policy, but response times may vary. If the malware is actively being used for harm, you may also consider reporting it to security organizations or CERT teams.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#68I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...
As another data point: MSFT have some sort of open mail server/service called onmicrosoft.com which (in my experience anyway) is only being used to send out fraudulent paypal messages. Because it lets the spammer set the From to service@paypal.com and also contains valid DKIM etc, it sails past spam filtering. There are so many complaints about this on (real) paypal.com forums, but Microsoft are apparently unable to…
Feels like just adding a direct "don't send as paypal, apple etc" rules would probably work though.
Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#69Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data
#70I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...
"We only sell the shovels, we don't use them, we don't think we have any holes needing dug."