Live data from Hacker News

Github scam investigation: Thousands of “mods” and “cracks” stealing data

timsh.org

61–70 of 165 posts

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#62
post #56
post #24

[flagged]

Gurn up, its 2025. Webpages have Javascript, get used to it. Run an adblocker if you care so much about it phoning home. And XHTML? The standard who's own governing body abandoned, why would anyone use that?

[flagged]

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#63
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

> The repos aren't themselves doing harm,

Yes they are. They are being used as delivery mechanism for malware.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#65
post #24

[flagged]

Is there such a right hosting, with noscript and basic html?

Yes. I use at least 2 of them... repo.or.cz, or rocketgit, and I guess they are many more.

Drop microsoft github and move there or similar.

But the best is to host yourself.

But careful, you are going against big tech interests, expect their shadow-paid hackers to attack you and any real-life alternative you use.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#67

If you've identified GitHub repositories hosting malware, you can report them directly to GitHub via their Abuse Report page, providing links and any relevant details. GitHub typically removes repositories that violate their Acceptable Use Policy, but response times may vary. If the malware is actively being used for harm, you may also consider reporting it to security organizations or CERT teams.

pretty sure this is an LLM generated comment

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#68
post #15
post #11

I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...

As another data point: MSFT have some sort of open mail server/service called onmicrosoft.com which (in my experience anyway) is only being used to send out fraudulent paypal messages. Because it lets the spammer set the From to service@paypal.com and also contains valid DKIM etc, it sails past spam filtering. There are so many complaints about this on (real) paypal.com forums, but Microsoft are apparently unable to…

onmicrosoft is "on microsoft" and is used behind the 365 company workspace. I have a onmicrosoft email for a 365 developer account, and anyone who connects to our company via teams seems to get a "{original_email}@{company}.onmicrosoft.com" ID setup, so I assume they're probably using it for things behind the scenes which also needs to void DKIM or something.

Feels like just adding a direct "don't send as paypal, apple etc" rules would probably work though.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#69
This raises a big question: How effective is GitHub’s abuse reporting system against large-scale malware campaigns? If 1,000+ malicious repos can persist for months, does this mean GitHub lacks automated scanning or relies too much on user reports?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#70
post #11

I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...

If only they had some kind of partnership with one of the big AI companies they might be able to leverage it to make their products, sorry, services better.

"We only sell the shovels, we don't use them, we don't think we have any holes needing dug."

Post reply on HN