logoalt Hacker News

n2d4last Sunday at 6:33 PM1 replyview on HN

It hides the malware's trail, and disguises which keys were leaked, making rotation harder


Replies

ack_inclast Monday at 11:20 AM

The socket.dev deconstruction of the worm (https://socket.dev/blog/shai-hulud-strikes-again-v2) suggests that the destructive actions on GitHub were not part of the malware itself.