Live data from Hacker News

I found 10k GitHub repositories distributing Trojan malware

orchidfiles.com

231–240 of 268 posts

Re: I found 10k GitHub repositories distributing Trojan malware

#233
post #211

Earlier quoted context omitted.

You'd be surprised as how there's individuals and organizations willing to pay a lot of money to do political manipulation / influencing.

> ... and organizations willing to pay a lot of money to do political manipulation / influencing. Like what, parties campaigning?

Pushing certain talking points, managing discourse, amplifying certain people/events/whatever. Not all of it is nation-state stuff, some things are just lobbying and influence-building and market manipulation. Spreading rumors for shady purposes is a very old scam.

Re: I found 10k GitHub repositories distributing Trojan malware

#234

This is happening to me as well. I have a few moderately popular open source projects and I have found my name attached to new projects that I have nothing to do with or they are derivatives of my projects with redirection to unknown sites. Legitimate projects: https://github.com/jimmc414/onefilellm https://github.com/jimmc414/Kosmos https://github.com/jimmc414/cctrace Projects using my name which I have no affiliati…

> Projects using my name which I have no affiliation with or they are projects I have written that they have injected new URLs into: How do you find these? I don't want to search for my name on those dodgy sites, as that tells them my projects exist.

For me these appeared to be indexed by Google, so a search with my GitHub username surfaced them.

Re: I found 10k GitHub repositories distributing Trojan malware

#235

Earlier quoted context omitted.

That's without considering a lot of banks have non-textual inputs for their passwords. Man they love their scrambled virtual keyboard! I think the worst I ever had was HSBC that asked me for fragments of my password, like characters 4, 6, 7, 11, and 12. Absolute bonkers of a security theatre.

How can they even do that without storing plaintext passwords?

It's a bank, and a rather old at that. I fully expect them to store the password in cleartext. (hence the security theatre qualification)

Banks are notorious for taking security as a strict cost/savings measure. I would not be surprised if they enforce weak passwords stored in cleartext on purpose to save on support agents for the people that forget/lose their password. Imagine the customer service reviews: "they were able to find my password back, 5/5". Probably enough savings to offset the cost of refunding people that got their account pwnd. Cost of doing business.

Re: I found 10k GitHub repositories distributing Trojan malware

#236

Earlier quoted context omitted.

That's without considering a lot of banks have non-textual inputs for their passwords. Man they love their scrambled virtual keyboard! I think the worst I ever had was HSBC that asked me for fragments of my password, like characters 4, 6, 7, 11, and 12. Absolute bonkers of a security theatre.

Oh I've never seen anything like that. But it would still help because my password manager pops up matching logins so you could just open that manually and then copy paste parts of it or type it in.

Definitely. If bitwarden does not shows a little "1" icon I'm basically lolnope'ing out.

Still, it pains me to see that practices from the early keylogger era are still "good practices".

Re: I found 10k GitHub repositories distributing Trojan malware

#237
post #216

Earlier quoted context omitted.

2 is full on speculation. It can be any kind of purpose.

I like how quickly this got dismissed as speculation as though we don't live in an age where election tampering and manipulation of public opinion for political reasons are so commonplace that incidents of it just blend in with the other forgettable global headlines.

Because it is speculation, with no special evidence. Could it be for just money? You can sell access to exploited systems in interesting companies for quite a bit of money. Or maybe it was for general use to twist public opinion in the future, not tied to those specific elections. Or just plain spying, We can't be sure, and the net was cast quite narrowly.

One could research where those repos are coming from, and do forensics on who controls the trojan network. But that wasn't done, so right now, it's all speculation. Something can be very worrying without us knowing exactly what the use cases for it will be

Re: I found 10k GitHub repositories distributing Trojan malware

#238
post #80
post #74

Being reminded of this anecdote from NYMag's recent cover story (which had previously been reported in a WSJ story[0]) about a Disney engineer who downloaded an AI-gen tool from Github and "checked the code himself, it had looked legitimate": https://archive.is/yAUNy > He had no idea why the hackers had targeted him or what their plan was, whether they would drain his family’s finances or stalk his home. Eventually,…

Strong support for the strategy of not putting your TOTP/MFA in your password manager, which has been argued on HN in the past.

At the very least, a different account for your password manager at work, hopefully paid by the company, which you don't install outside of company-controlled devices.
Post reply on HN