4 ms·
The actual inclusion code was never in the repo. The blobs were hidden as lzma test files. So you review would need to guess from 2 new test files that those a
by treffer 2y ago
The actual inclusion code was never in the repo. The blobs were hidden as lzma test files.
So you review would need to guess from 2 new test files that those are, decompressed, a backdoor and could be injected which was never in the git history.
This was explicitly build to evade such reviews.
- xghryro 2y agoI suppose you think the maintainers shouldn’t have scrutinized those files? Please tell me it’s a joke.
- ab5tract 2y agoThe person who added the malicious blobs and signed the compromized archives was literally a maintainer of the project.
- account42 2y agoOk, go ahead and scrutinize those files without looking at the injection code that was never in the repo? Can you find anything malicious? Probably not - it looks like random garbage which is what it was claimed to be.
- pmarreck 2y ago> The blobs were hidden as lzma test files. OK, that is absolutely devious.