I found 10k GitHub repositories distributing Trojan malware
241–250 of 268 posts
Re: I found 10k GitHub repositories distributing Trojan malware
#242Earlier quoted context omitted.
I like how quickly this got dismissed as speculation as though we don't live in an age where election tampering and manipulation of public opinion for political reasons are so commonplace that incidents of it just blend in with the other forgettable global headlines.
Because it is speculation, with no special evidence. Could it be for just money? You can sell access to exploited systems in interesting companies for quite a bit of money. Or maybe it was for general use to twist public opinion in the future, not tied to those specific elections. Or just plain spying, We can't be sure, and the net was cast quite narrowly. One could research where those repos are coming from, and do…
Re: I found 10k GitHub repositories distributing Trojan malware
#243Earlier quoted context omitted.
"Dang, this site isn't working right with the password manager's detection. Guess I just gotta paste the password in again..." Meanwhile U2F/Passkeys can't possibly be abused like this.
Yeah but the downsides of passkeys make them so much worse anyway.
Re: I found 10k GitHub repositories distributing Trojan malware
#244Earlier quoted context omitted.
2 is full on speculation. It can be any kind of purpose.
I like how quickly this got dismissed as speculation as though we don't live in an age where election tampering and manipulation of public opinion for political reasons are so commonplace that incidents of it just blend in with the other forgettable global headlines.
… you also have to remember that the JTRIG leaked docs were about a decade before LLMs, so you could imagine tooling these days is 100x a they used to have
Re: I found 10k GitHub repositories distributing Trojan malware
#245> Why do they only clone new repositories, rather than popular ones? > Why do they delete a commit and push a new one every few hours? Because this is not targetted to humans. It's targetted to agents. They just need to appear on a fraction of the searches agents do to add dependencies and get lucky a couple times to start a new infection cluster. Then to the more interesting question: why now? 1. Agents, agents ever…
Re: I found 10k GitHub repositories distributing Trojan malware
#246Earlier quoted context omitted.
I like how quickly this got dismissed as speculation as though we don't live in an age where election tampering and manipulation of public opinion for political reasons are so commonplace that incidents of it just blend in with the other forgettable global headlines.
Because it is speculation, with no special evidence. Could it be for just money? You can sell access to exploited systems in interesting companies for quite a bit of money. Or maybe it was for general use to twist public opinion in the future, not tied to those specific elections. Or just plain spying, We can't be sure, and the net was cast quite narrowly. One could research where those repos are coming from, and do…
Re: I found 10k GitHub repositories distributing Trojan malware
#247Re: I found 10k GitHub repositories distributing Trojan malware
#248Re: I found 10k GitHub repositories distributing Trojan malware
#249Re: I found 10k GitHub repositories distributing Trojan malware
#250This is happening to me as well. I have a few moderately popular open source projects and I have found my name attached to new projects that I have nothing to do with or they are derivatives of my projects with redirection to unknown sites. Legitimate projects: https://github.com/jimmc414/onefilellm https://github.com/jimmc414/Kosmos https://github.com/jimmc414/cctrace Projects using my name which I have no affiliati…
Idk if this is intentional or just part of an innocent site that’s unwittingly hosting these but I just got a “we’re verifying your browser” page, as if _I’m_ the suspicious one. Nice social engineering.