Live data from Hacker News

I found 10k GitHub repositories distributing Trojan malware

orchidfiles.com

251–260 of 268 posts

Re: I found 10k GitHub repositories distributing Trojan malware

#251

> Why do they only clone new repositories, rather than popular ones? > Why do they delete a commit and push a new one every few hours? Because this is not targetted to humans. It's targetted to agents. They just need to appear on a fraction of the searches agents do to add dependencies and get lucky a couple times to start a new infection cluster. Then to the more interesting question: why now? 1. Agents, agents ever…

While 2 is possible, we've had automated ransomware going for some time now. The agents in 1 are sufficient.

Re: I found 10k GitHub repositories distributing Trojan malware

#252

Earlier quoted context omitted.

Idk if this is intentional or just part of an innocent site that’s unwittingly hosting these but I just got a “we’re verifying your browser” page, as if _I’m_ the suspicious one. Nice social engineering.

Microsoft bought it a while ago. What you're seeing is referred to as "Extinguish".

Microsoft bought Vercel???

Re: I found 10k GitHub repositories distributing Trojan malware

#254

> Why do they only clone new repositories, rather than popular ones? > Why do they delete a commit and push a new one every few hours? Because this is not targetted to humans. It's targetted to agents. They just need to appear on a fraction of the searches agents do to add dependencies and get lucky a couple times to start a new infection cluster. Then to the more interesting question: why now? 1. Agents, agents ever…

Political manipulation is a problem, but I don't think it's nearly as profitable as pushing scams and gambling.

It doesn’t need to be profitable if it’s cheap - political manipulation by unsavory parties is worth a cheap botnet if it means they can keep power and keep grifting.

I will agree with a sibling up there that the political part is pure speculation, and I’d guess anyone running a moderately sized botnet is open to use for any nefarious purposes if the price is right.

Re: I found 10k GitHub repositories distributing Trojan malware

#255

Same thing happened to one of my repos in Feb. I wrote up the details with screenshots. https://reducibl.com/writing/someone-used-my-repo-to-distrib...

Thanks for the writing, which would have been even better had it been written by a human.

Re: I found 10k GitHub repositories distributing Trojan malware

#256
post #211

Earlier quoted context omitted.

> ... and organizations willing to pay a lot of money to do political manipulation / influencing. Like what, parties campaigning?

We're talking about foreign influence here. All recent US and German elections reeked of Russian dark money, then there was the entire Cambridge Analytica mess and before that it was Brexit.

Not every result you dislike is "Russian inference".

Re: I found 10k GitHub repositories distributing Trojan malware

#257

Same thing happened to one of my repos in Feb. I wrote up the details with screenshots. https://reducibl.com/writing/someone-used-my-repo-to-distrib...

Thanks for the writing, which would have been even better had it been written by a human.

Why do you think it wasn't written by a human?

Re: I found 10k GitHub repositories distributing Trojan malware

#258

Earlier quoted context omitted.

Thanks for the writing, which would have been even better had it been written by a human.

Why do you think it wasn't written by a human?

Have you read the article?

> that’s not a developer contributing to open source. that’s someone manufacturing the appearance of activity.

> the attacker’s own profile? no bio, no avatar, 499 contributions crammed into january–february 2026.

> this wasn’t random

> i reported the repo to github. the ticket is open. but this raises a question i keep coming back to

Re: I found 10k GitHub repositories distributing Trojan malware

#259

Earlier quoted context omitted.

Why do you think it wasn't written by a human?

Have you read the article? > that’s not a developer contributing to open source. that’s someone manufacturing the appearance of activity. > the attacker’s own profile? no bio, no avatar, 499 contributions crammed into january–february 2026. > this wasn’t random > i reported the repo to github. the ticket is open. but this raises a question i keep coming back to

Thanks. I checked the text using the gptzero service. It shows that 100% of the text was generated by AI. I removed the link from my article.

I checked out the other pages on his website. And his other articles. AI-generated content is absolutely everywhere.

Oh, I'm so tired of AI-generated texts.

Re: I found 10k GitHub repositories distributing Trojan malware

#260
post #216

Earlier quoted context omitted.

2 is full on speculation. It can be any kind of purpose.

I like how quickly this got dismissed as speculation as though we don't live in an age where election tampering and manipulation of public opinion for political reasons are so commonplace that incidents of it just blend in with the other forgettable global headlines.

that things happen doesnt mean you do not need evidence 0xEF. No evidence was presented, so its speculation. It is _much_ more common to do other things than election tampering as desired effect of cyber activities. The amount of election tampering activities is statistically insignificant to other activities conducted in this domain.
Post reply on HN