logoalt Hacker News

grekowalskilast Wednesday at 9:55 PM2 repliesview on HN

Recently, those Monero miners were installing themselves everywhere that had a vulnerable React 19. I had exactly the same problem.


Replies

tgsovlerkhgselyesterday at 7:45 AM

I love mining malware - it's reasonably visible and causes almost no damage. Essentially, it's like a bug bounty program that you don't have to manage, doesn't generate costly bullshit reports, and only costs you a few bucks of electricity when a vulnerability is found.

If you have decent network or process level monitoring, you're likely to find it, while you might not realize the vulnerable software itself or some stealthier, more dangerous malware that might exploit it.

qingcharleslast Wednesday at 10:27 PM

I had to nuke my Oracle Cloud box that runs my Umami server. It got hit. Was a good excuse to upgrade version and upgrade all my backup systems etc. Lost a few hours of data while it was returning 500 errors.