logoalt Hacker News

mmsctoday at 1:35 PM1 replyview on HN

> Another month later, GitHub support sent me an email saying that they had removed these repositories.

I recently discovered a campaign where somebody was forking very small but useful codebases, and replacing the distributable with some malware, and making the repository have better SEO with changes to the README. My case was a simple macOS application that could be used to control some Phillips LED light strip.

I reported it to GitHub and it was removed within 24 hours.

I discovered another repository like this, and they still haven't replied since (one month).

No clue how their malware reports work. I'm surprised they don't partner with some antivirus company to at least scan "releases" for malware (not repositories themselves)


Replies

mrbluecoattoday at 3:24 PM

> I'm surprised they don't partner with some antivirus company to at least scan "releases" for malware

...like Windows Defender? Oh, the irony :D