Live data from Hacker News

Keylogger discovered in image generator extension

old.reddit.com

1–10 of 102 posts

Re: Keylogger discovered in image generator extension

#4
Some entity called Nullbulge Group claims they took over the repo.

Today's capture (before the repo got 404'd) has their belligerence spiel. https://web.archive.org/web/20240609135118/https://github.co...

This is the capture from 3 days prior: https://web.archive.org/web/20240525021402/https://github.co...

Re: Keylogger discovered in image generator extension

#5
post #3

Looks like a pretty small project. Only had 40 stars on GitHub before the repo was removed. Was this the main method of GPT4 and Claude integrations for ComfyUI?

It was an extension for ComfyUI, which has 37k stars on GitHub. The way ComfyUI is commonly used is that a person shares a "workflow" file, which utilizes various obscure extensions (called "custom nodes") and then the people who want to run the workflow on their own computer will install all these obscure custom nodes that have like 40 stars on GitHub or so.

Re: Keylogger discovered in image generator extension

#6

Some entity called Nullbulge Group claims they took over the repo. Today's capture (before the repo got 404'd) has their belligerence spiel. https://web.archive.org/web/20240609135118/https://github.co... This is the capture from 3 days prior: https://web.archive.org/web/20240525021402/https://github.co...

I have not seen a statement from Nullbulge so it's not appropriate to say that they took over the repo.

The author of the repo is claiming that their repo is hacked, but this is an obvious lie, because their very first GitHub commit is the one where they push the malware. Nobody would hack an empty GitHub account.

I don't know if the author of the repo is lying when they say that Nullbulge is behind the attack (perhaps the author is part of Nullbulge, perhaps not).

Re: Keylogger discovered in image generator extension

#10

Some entity called Nullbulge Group claims they took over the repo. Today's capture (before the repo got 404'd) has their belligerence spiel. https://web.archive.org/web/20240609135118/https://github.co... This is the capture from 3 days prior: https://web.archive.org/web/20240525021402/https://github.co...

I have not seen a statement from Nullbulge so it's not appropriate to say that they took over the repo. The author of the repo is claiming that their repo is hacked, but this is an obvious lie, because their very first GitHub commit is the one where they push the malware. Nobody would hack an empty GitHub account. I don't know if the author of the repo is lying when they say that Nullbulge is behind the attack (perha…

I wouldn't be so sure no one would hack an idle account. I had my Spotify account taken before I even used it. I think in my case they used my account to pump up other lesser known artists.
Post reply on HN