Live data from Hacker News

I found 10k GitHub repositories distributing Trojan malware

orchidfiles.com

241–250 of 268 posts

Re: I found 10k GitHub repositories distributing Trojan malware

#242
post #216

Earlier quoted context omitted.

I like how quickly this got dismissed as speculation as though we don't live in an age where election tampering and manipulation of public opinion for political reasons are so commonplace that incidents of it just blend in with the other forgettable global headlines.

Because it is speculation, with no special evidence. Could it be for just money? You can sell access to exploited systems in interesting companies for quite a bit of money. Or maybe it was for general use to twist public opinion in the future, not tied to those specific elections. Or just plain spying, We can't be sure, and the net was cast quite narrowly. One could research where those repos are coming from, and do…

Speculation: It probably is just for money. Then the ppl buying, at least some of them, are likely to be engaging in the type of activity described.

Re: I found 10k GitHub repositories distributing Trojan malware

#243
post #23

Earlier quoted context omitted.

"Dang, this site isn't working right with the password manager's detection. Guess I just gotta paste the password in again..." Meanwhile U2F/Passkeys can't possibly be abused like this.

Yeah but the downsides of passkeys make them so much worse anyway.

Passkeys are great. Store them in your password manager and what downsides are you referring to

Re: I found 10k GitHub repositories distributing Trojan malware

#244
post #216

Earlier quoted context omitted.

2 is full on speculation. It can be any kind of purpose.

I like how quickly this got dismissed as speculation as though we don't live in an age where election tampering and manipulation of public opinion for political reasons are so commonplace that incidents of it just blend in with the other forgettable global headlines.

Why would they steal credentials when governments already have fake accounts for this exact purpose (see UK’s JTRIG from the Snowden documents)

… you also have to remember that the JTRIG leaked docs were about a decade before LLMs, so you could imagine tooling these days is 100x a they used to have

Re: I found 10k GitHub repositories distributing Trojan malware

#245

> Why do they only clone new repositories, rather than popular ones? > Why do they delete a commit and push a new one every few hours? Because this is not targetted to humans. It's targetted to agents. They just need to appear on a fraction of the searches agents do to add dependencies and get lucky a couple times to start a new infection cluster. Then to the more interesting question: why now? 1. Agents, agents ever…

[flagged]

Re: I found 10k GitHub repositories distributing Trojan malware

#246
post #216

Earlier quoted context omitted.

I like how quickly this got dismissed as speculation as though we don't live in an age where election tampering and manipulation of public opinion for political reasons are so commonplace that incidents of it just blend in with the other forgettable global headlines.

Because it is speculation, with no special evidence. Could it be for just money? You can sell access to exploited systems in interesting companies for quite a bit of money. Or maybe it was for general use to twist public opinion in the future, not tied to those specific elections. Or just plain spying, We can't be sure, and the net was cast quite narrowly. One could research where those repos are coming from, and do…

Indeed, and it troubles me that people don't know the difference between speculation (no matter how plausible) and analysis based on evidence. The anti-science movement (or impulse) is still pervasive, unfortunately.

Re: I found 10k GitHub repositories distributing Trojan malware

#249

Same thing happened to one of my repos in Feb. I wrote up the details with screenshots. https://reducibl.com/writing/someone-used-my-repo-to-distrib...

Did Github ever do anything?

Yea, they removed the fork <24 hours after I reported it

Re: I found 10k GitHub repositories distributing Trojan malware

#250

This is happening to me as well. I have a few moderately popular open source projects and I have found my name attached to new projects that I have nothing to do with or they are derivatives of my projects with redirection to unknown sites. Legitimate projects: https://github.com/jimmc414/onefilellm https://github.com/jimmc414/Kosmos https://github.com/jimmc414/cctrace Projects using my name which I have no affiliati…

Idk if this is intentional or just part of an innocent site that’s unwittingly hosting these but I just got a “we’re verifying your browser” page, as if _I’m_ the suspicious one. Nice social engineering.

Microsoft bought it a while ago. What you're seeing is referred to as "Extinguish".
Post reply on HN