6 ms·
Many of the repos I found were clones of valid projects with same names under new orgs and new users. For instance, this projects is valid: https://github.com/s
by stevelacy 4y ago
Many of the repos I found were clones of valid projects with same names under new orgs and new users.
For instance, this projects is valid: https://github.com/scala-network/GUI-miner https://github.com/scala-network/GUI-miner
and it's infected clone: https://github.com/stellitecoin/gui-miner https://github.com/stellitecoin/gui-miner
GPG signed commits by the legitimate users do not contain the malware
- laserlight 4y agoConsidering that only clones are affected, your original tweet is downright wrong. None of the listed projects (python, js, bash, docker, k8s) are affected. Anybody can fork a repository to introduce malware.
- eurasiantiger 4y agojs is a project?
- laserlight 4y agoYou're right. It's not. I just copy-pasted the list from the tweet. I assume that the author meant to write jq.