Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Linux
  3. Supply chain attack on Github, malware injected in fork ransomwares Linux machines

Supply chain attack on Github, malware injected in fork ransomwares Linux machines

Scheduled Pinned Locked Moved Linux
linux
37 Posts 27 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • O [email protected]

    oh oh, I'm a below average arch user.
    I suspect i copied most of my hoome from debian or something.

    I'll rename it to Dickuments as a security feature.

    L This user is from outside of this forum
    L This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #23

    Hackers gonna wanna Netflix and chill

    1 Reply Last reply
    0
    • ikidd@lemmy.worldI [email protected]

      Apparently there's a bunch of projects getting hit with this, fairly obscure ones though. Project gets forked, suddenly get a pile of stars more than the original, and then there's a curl-bash pipe inserted into it that runs some ransomeware that encrypts ~/Documents.

      About a dozen other projects linked in here from another developer (excuse the Reddit link): https://www.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/

      aatube@kbin.melroy.orgA This user is from outside of this forum
      aatube@kbin.melroy.orgA This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #24

      Finally, Linux is popular enough to get targeted by malware!

      sturgist@lemmy.caS 1 Reply Last reply
      0
      • ikidd@lemmy.worldI [email protected]

        Apparently there's a bunch of projects getting hit with this, fairly obscure ones though. Project gets forked, suddenly get a pile of stars more than the original, and then there's a curl-bash pipe inserted into it that runs some ransomeware that encrypts ~/Documents.

        About a dozen other projects linked in here from another developer (excuse the Reddit link): https://www.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/

        P This user is from outside of this forum
        P This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #25

        Yay, finally Linux is being attacked!

        And as expected it takes whole lot more than clicking on an email attachment

        Always check before you curl download something!

        R 1 Reply Last reply
        0
        • ikidd@lemmy.worldI [email protected]

          Apparently there's a bunch of projects getting hit with this, fairly obscure ones though. Project gets forked, suddenly get a pile of stars more than the original, and then there's a curl-bash pipe inserted into it that runs some ransomeware that encrypts ~/Documents.

          About a dozen other projects linked in here from another developer (excuse the Reddit link): https://www.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/

          L This user is from outside of this forum
          L This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #26

          ...the fuck is that title? I got a headache trying to make sense of it.

          ikidd@lemmy.worldI 1 Reply Last reply
          0
          • L [email protected]

            ...the fuck is that title? I got a headache trying to make sense of it.

            ikidd@lemmy.worldI This user is from outside of this forum
            ikidd@lemmy.worldI This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #27

            Yah, I read it afterwards and realized I'd verbed a noun. I'm not proud of it.

            kurumin@linux.communityK 1 Reply Last reply
            0
            • ikidd@lemmy.worldI [email protected]

              Apparently there's a bunch of projects getting hit with this, fairly obscure ones though. Project gets forked, suddenly get a pile of stars more than the original, and then there's a curl-bash pipe inserted into it that runs some ransomeware that encrypts ~/Documents.

              About a dozen other projects linked in here from another developer (excuse the Reddit link): https://www.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/

              A This user is from outside of this forum
              A This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #28

              I keep saying this curl bash pipe shit needs to stop.

              G 1 Reply Last reply
              0
              • ikidd@lemmy.worldI [email protected]

                Apparently there's a bunch of projects getting hit with this, fairly obscure ones though. Project gets forked, suddenly get a pile of stars more than the original, and then there's a curl-bash pipe inserted into it that runs some ransomeware that encrypts ~/Documents.

                About a dozen other projects linked in here from another developer (excuse the Reddit link): https://www.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/

                eager_eagle@lemmy.worldE This user is from outside of this forum
                eager_eagle@lemmy.worldE This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #29

                good time to not have a ~/Documents and keep backups encrypted off site

                1 Reply Last reply
                0
                • ikidd@lemmy.worldI [email protected]

                  Yah, I read it afterwards and realized I'd verbed a noun. I'm not proud of it.

                  kurumin@linux.communityK This user is from outside of this forum
                  kurumin@linux.communityK This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #30

                  Here in Lemmy you can edit titles

                  1 Reply Last reply
                  0
                  • ikidd@lemmy.worldI [email protected]

                    Apparently there's a bunch of projects getting hit with this, fairly obscure ones though. Project gets forked, suddenly get a pile of stars more than the original, and then there's a curl-bash pipe inserted into it that runs some ransomeware that encrypts ~/Documents.

                    About a dozen other projects linked in here from another developer (excuse the Reddit link): https://www.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/

                    ? Offline
                    ? Offline
                    Guest
                    wrote on last edited by
                    #31

                    That simply wouldn't work in non-english machines lmao

                    S 1 Reply Last reply
                    0
                    • P [email protected]

                      Yay, finally Linux is being attacked!

                      And as expected it takes whole lot more than clicking on an email attachment

                      Always check before you curl download something!

                      R This user is from outside of this forum
                      R This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #32

                      No. Feel free to download shit and even attempt to run shit. Chances are they won't run because shits are compiled against glibc and my system is not.

                      1 Reply Last reply
                      0
                      • ? Guest

                        That simply wouldn't work in non-english machines lmao

                        S This user is from outside of this forum
                        S This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #33

                        Maybe they're using xdg-dirs? That might work, won't it?

                        1 Reply Last reply
                        0
                        • ikidd@lemmy.worldI [email protected]

                          Apparently there's a bunch of projects getting hit with this, fairly obscure ones though. Project gets forked, suddenly get a pile of stars more than the original, and then there's a curl-bash pipe inserted into it that runs some ransomeware that encrypts ~/Documents.

                          About a dozen other projects linked in here from another developer (excuse the Reddit link): https://www.reddit.com/r/golang/comments/1jbzuot/someone_copied_our_github_project_made_it_look/

                          G This user is from outside of this forum
                          G This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #34

                          Why the Documents folder tho? Who expects important stuff to be there?

                          Now all my Linux ISOs are gone, smh

                          1 Reply Last reply
                          0
                          • A [email protected]

                            I keep saying this curl bash pipe shit needs to stop.

                            G This user is from outside of this forum
                            G This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #35

                            Yes, I agree, but then, what would be an alternative?

                            Store it into a file, chmod it and run it? git clone the repo and run a script from it? I don't think any of those would be different, apart from having more steps most people won't even check anything.

                            I don't know if we can fix this while allowing people to run stuff they don't understand on their machines. Maybe community curated scripts or something, know the people who does the stuff and only run stuff made by people you already know.

                            I think we're running too fast, we need to chill down, idk.

                            A 1 Reply Last reply
                            0
                            • G [email protected]

                              Yes, I agree, but then, what would be an alternative?

                              Store it into a file, chmod it and run it? git clone the repo and run a script from it? I don't think any of those would be different, apart from having more steps most people won't even check anything.

                              I don't know if we can fix this while allowing people to run stuff they don't understand on their machines. Maybe community curated scripts or something, know the people who does the stuff and only run stuff made by people you already know.

                              I think we're running too fast, we need to chill down, idk.

                              A This user is from outside of this forum
                              A This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #36

                              Yes, I agree, but then, what would be an alternative?

                              Any package manager that allows for ways to verify the source. These shitty script|bash lines are doing all sorts of nutty shit on your system, and that's ones that aren't even malicious.

                              1 Reply Last reply
                              0
                              • aatube@kbin.melroy.orgA [email protected]

                                Finally, Linux is popular enough to get targeted by malware!

                                sturgist@lemmy.caS This user is from outside of this forum
                                sturgist@lemmy.caS This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #37

                                Year of Linux wen? Now? Ples, B now?

                                1 Reply Last reply
                                0
                                • System shared this topic on
                                Reply
                                • Reply as topic
                                Log in to reply
                                • Oldest to Newest
                                • Newest to Oldest
                                • Most Votes


                                • Login

                                • Login or register to search.
                                • First post
                                  Last post
                                0
                                • Categories
                                • Recent
                                • Tags
                                • Popular
                                • World
                                • Users
                                • Groups