Live data from Hacker News

I found 10k GitHub repositories distributing Trojan malware

orchidfiles.com

81–90 of 268 posts

Re: I found 10k GitHub repositories distributing Trojan malware

#81
> Why do they only clone new repositories, rather than popular ones? > Why do they delete a commit and push a new one every few hours?

Because this is not targetted to humans. It's targetted to agents. They just need to appear on a fraction of the searches agents do to add dependencies and get lucky a couple times to start a new infection cluster.

Then to the more interesting question: why now?

1. Agents, agents everywhere.

2. MAJOR elections happening this year in the World, including US midterms and Brazilian mains. This appears to be an account-stealer worm - and my guess is it's looking to all those sweet sweet Facebook/Instagram/Tiktok/Whatsapp accounts ready to bot their way into oblivion.

Re: I found 10k GitHub repositories distributing Trojan malware

#82

the en-ghettofication of american tech, down to its very open source control projects. a digital ghetto ill maintained if at all.

There’s nothing new here. This is how open source software has been since its inception. It’s just the nature of reality.

Re: I found 10k GitHub repositories distributing Trojan malware

#83

I have to say, the principle that open-source software can't do anything nefarious because the source is open just hasn't held up for a lot of reasons -- including that nobody has the time to inspect the code, let alone ensure that it matches the binaries; and also that GitHub has become a distribution hub for software used by lots of people with no ability or interest in auditing the software they use.

Why the hell do you think this is related to open-source software?

Re: I found 10k GitHub repositories distributing Trojan malware

#84
post #25

Microsoft: and the one thing we absolutely refuse to use AI for is to flag this kind of bullshit to protect users, because it would violate the rule of "don't do anything actually useful with it".

You can bet they’ve tried it and had a bunch of false positives, so the PM nixed it because it would be bad for business.

Re: I found 10k GitHub repositories distributing Trojan malware

#85

Earlier quoted context omitted.

No, I've not been "living on" such a principle but it was a big claim for "the bazaar."

You'd better read it again, because that claim does not figure in that text. You might mean that with more eyes on the code, more bugs are found, than with no eyes on the code. But that is not what you are saying here.

Here is the relevant quote from _The Cathedral and the Bazaar_[1], which was given the name _Linus's Law_[2] in honor of Linus Torvalds:

> Given enough eyeballs, all bugs are shallow.

[1] http://www.catb.org/~esr/writings/cathedral-bazaar/cathedral...

[2] https://en.wikipedia.org/wiki/Linus%27s_law

Re: I found 10k GitHub repositories distributing Trojan malware

#86
post #80
post #74

Being reminded of this anecdote from NYMag's recent cover story (which had previously been reported in a WSJ story[0]) about a Disney engineer who downloaded an AI-gen tool from Github and "checked the code himself, it had looked legitimate": https://archive.is/yAUNy > He had no idea why the hackers had targeted him or what their plan was, whether they would drain his family’s finances or stalk his home. Eventually,…

Strong support for the strategy of not putting your TOTP/MFA in your password manager, which has been argued on HN in the past.

> putting your TOTP/MFA in your password manager

I suppose the inverse would be starting with a device that offers TOTP/MFA, and then making your password-manager/vault somehow available on that same device. In either case, bringing them together makes it easier for an attacker to compromise both at the same time.

On reflection, I've never actually put my (personal) password vault on my phone, but that may be less of a conscious security stance than fulfilling a millennial stereotype, where certain tasks (like big purchases) are reserved for "a real computer."

Closest I've gotten is having my USB backup keychain in the same pocket, so I could get to it in an emergency, but it's inconveniently air-gapped.

Re: I found 10k GitHub repositories distributing Trojan malware

#87

Earlier quoted context omitted.

No, it's really not, and really hasn't been. Do people truly have such poor reasoning and logic skills? "Closed source software is inscrutable, impossible for me to fix, impossible for me to review the source" is absolutely a distinct statement from "it is impossible to hide malware in open-source software". I've literally never heard someone claim the latter. (edit for coherency, thanks graemep)

> "it is impossible to hide malware in open-source software" No nobody said "exactly that". But many times I've seen people claiming to trust open source as it is safer and people can check and build themselves. Seen it too many times. But reality is different than what is claimed.

It's safer in the same sense as if you're paranoid about your date being a serial killer, you meet them in a public venue. It doesn't mean your date isn't a serial killer, but the risk profile is different because other people can be involved/witness/have context.

You didn't use the word "safe", you used the relative term "safer", and on average, it is harder to hide ill intent in open source software, there's a greater chance it will eventually be discovered. The blast radius is larger for open source (because the barrier to using it is lower), which increases the number of people impacted, but an increase in the number of people impacted also increases the chance of discovery and motivation to address it once discovered.

Re: I found 10k GitHub repositories distributing Trojan malware

#88
post #80
post #74

Being reminded of this anecdote from NYMag's recent cover story (which had previously been reported in a WSJ story[0]) about a Disney engineer who downloaded an AI-gen tool from Github and "checked the code himself, it had looked legitimate": https://archive.is/yAUNy > He had no idea why the hackers had targeted him or what their plan was, whether they would drain his family’s finances or stalk his home. Eventually,…

Strong support for the strategy of not putting your TOTP/MFA in your password manager, which has been argued on HN in the past.

Or using a hardware authenticator.

Re: I found 10k GitHub repositories distributing Trojan malware

#89

Earlier quoted context omitted.

> You've been living on such a principle? I have not, but in case you missed it, this principle has been used by open source proponents for decades. I'm an open source developer myself, but always found it odd.

No, it's really not, and really hasn't been. Do people truly have such poor reasoning and logic skills? "Closed source software is inscrutable, impossible for me to fix, impossible for me to review the source" is absolutely a distinct statement from "it is impossible to hide malware in open-source software". I've literally never heard someone claim the latter. (edit for coherency, thanks graemep)

I genuinely don't understand what you are trying to say.

Re: I found 10k GitHub repositories distributing Trojan malware

#90

the en-ghettofication of american tech, down to its very open source control projects. a digital ghetto ill maintained if at all.

There’s nothing new here. This is how open source software has been since its inception. It’s just the nature of reality.

This story is totally unrelated to open-source. There is no mention of a source let alone a license.
Post reply on HN