logoalt Hacker News

KomoDlast Sunday at 4:04 PM2 repliesview on HN

Doesn't it publish the repos to your Github account? Just clone and look at what was stolen.


Replies

solrithlast Sunday at 4:25 PM

On the follow up Wiz blog they suggested that the exfiltration was cross-victim https://www.wiz.io/blog/shai-hulud-2-0-aftermath-ongoing-sup...

bspammerlast Sunday at 5:35 PM

As the sibling comment said, the worm used stolen GitHub credentials from other victims, and randomly distributed the uploads between victims.

Also everything was double base64 encoded which makes it impossible to use GitHub search.