Live data from Hacker News

Github scam investigation: Thousands of “mods” and “cracks” stealing data

timsh.org

71–80 of 165 posts

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#71
Some time ago i was asked to help installing a mode for Plants vs. Zombies - a PVZ Fusion mode.

When searching for it I found multiple, some had download from github repos. None was looking trustworthy enough, so I didnt download any. But I hesitated a little.

From how they looked, I think now that was the kind of malware the author describes.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#72
post #2

Why should malware repos be deleted? Serious question. The repos aren't themselves doing harm, are valuable for research, and would be distributed some other way if GH removed them. Maybe a banner “be careful! others have reported that this repo may not do what it claims. proceed with caution” would be a more appropriate response?

> The repos aren't themselves doing harm,

Yes they are. Did you read the part about the people doing this and getting 50-100 compromised computers per day? They’re stealing accounts and crypto with these.

> are valuable for research,

Research into how they’re harming people? The research is done. Time to move to fixing it.

> and would be distributed some other way if GH removed them.

This is like saying we shouldn’t wear seatbelts because some people will still die in car crashes anyway.

You don’t avoid improving a situation just because you can’t perfectly fix it globally. You address what you can and reduce the problem.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#73
post #49

Earlier quoted context omitted.

What is the definition of distribution? If I posted a code snippet of malware on github or my personal site for educational purposes, does that count as distribution?

That depends heavily on the law in question. Germany e.g. almost completely bans white hat activities because hacking is evil, and no amount of common sense has been able to get through lawmakers' thick skulls.

You can downvote him all you want, but it's true at the core. §202c of the BGB heavily limits what can be done, even by legit researchers, and it's often being critized for that reason.

For anyone interested, the Wikipedia article might give an overview (only available in German right now): https://de.wikipedia.org/wiki/Vorbereiten_des_Aussp%C3%A4hen...

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#74
post #11

I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...

but this comment is gold :D

> Sounds like deleting a VM in Azure is as tedious as trying to manage resources in a complex role-playing game—one wrong step, and you’re stuck dealing with frustrating dependencies! If you’re tired of that kind of hassle, maybe it’s time to switch things up with Download SpinRP. Instead of deleting VMs in the right order, you can dive into an immersive world where strategy and excitement go hand in hand. Why deal with a “big fat pink error” when you could be making big moves in SpinRP instead?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#75
These repos post to Discord webhooks to notify of newly compromised systems.

I’ve found Discord to be responsive to abuse complaints in the past. If someone wrote a simple script to download these repos and extract the Discord webhook links I bet you could get Discord to shut down their accounts.

In my past experience Discord was aggressive about this, going so far as to ban the accounts of people who had participated on those servers with clearly illegal purposes. They’ll come back and make new accounts again, of course, but having them lose all of their connected servers, history, and requiring them to update every single one of their malware drops should slow them down considerably.

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#76
post #11

I think Microsoft has a general problem with getting rid of unwanted things within their eco-system. I keep complaining that their feedback.azure.com portal is filled with spam/malware comments and links, but even internally their teams can't reach anyone to get it fixed. Example https://feedback.azure.com/d365community/idea/9d0b22d8-c025-...

> 9 years ago > This is still coming. The work is being completed now and we will be able to expose it in a few months. I'm glad the official response has no date associated, so you won't know whether they published that yesterday of 8 years ago.

Looks bad either way

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#78
post #57
post #15

Earlier quoted context omitted.

As another data point: MSFT have some sort of open mail server/service called onmicrosoft.com which (in my experience anyway) is only being used to send out fraudulent paypal messages. Because it lets the spammer set the From to service@paypal.com and also contains valid DKIM etc, it sails past spam filtering. There are so many complaints about this on (real) paypal.com forums, but Microsoft are apparently unable to…

I think I read somewhere that scammers set up an email distribution list / alias / forwarding from one something.onmicrosoft.com account to dozens of victims, and then they trigger a (real!) paypal email with that one something.onmicrosoft.com address as the recipient. So the email has a valid DKIM signature from paypal, then microsoft forwards that email to all the victims, which will still pass DKIM while amplifyin…

Is there a legitimate reason for them to forward paypal emails? Why not just not let that happen under any circumstances?

Re: Github scam investigation: Thousands of “mods” and “cracks” stealing data

#80
post #7

Earlier quoted context omitted.

Doesn't distributing malware break a number of laws?

What is the definition of distribution? If I posted a code snippet of malware on github or my personal site for educational purposes, does that count as distribution?

Really? The malware went from your computer to someone else's and your defense is that it was not "distributed" but just magically moved from A to B?

If you argued that it was clearly labeled as malware for educational purposes, that seems fine. It was distributed, but then distribution is allowed. But this is very clearly not the case here.

Post reply on HN