logoalt Hacker News

OldMateyyesterday at 10:49 AM4 repliesview on HN

Given the time and effort that went into this, and the luck that one diligent person noticed, investigated and discovered what was going on before it could get further... it seems very likely to me that this has happened already in other libraries without being discovered.


Replies

VladVladikoffyesterday at 12:48 PM

I wonder if the nation state actors are doing people profiling on owners of important packages to find the most vulnerable for an attack.

mirambayesterday at 10:52 AM

Exactly, and I wonder since then: How closely did people in comparable situations look? Since nothing similar has been reported, I suspect not very close…

IshKebabyesterday at 2:22 PM

The effort of gaining trust over an existing project isn't even really required. All you need to do is monitor when popular GitHub repos get archived. That's usually when the original authors don't want to work on it any more. Then just quickly make a fork to continue the project (think Phabricator -> Phorge), and if you're quick enough and authoritative sounding enough, boom control of the project!

Maintain it for a bit so people switch to your version, and job done.

akimbostrawmanyesterday at 1:15 PM

Anybody running opensnitch would notice