LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-01-2024, 07:47 AM   #1
Jan K.
Member
 
Registered: Apr 2019
Location: Esbjerg
Distribution: Windows 7...
Posts: 773

Rep: Reputation: 489Reputation: 489Reputation: 489Reputation: 489Reputation: 489
Exclamation Malware campaign on GitHub...


Quote:
A malware distribution campaign that began last May with a handful of malicious software packages uploaded to the Python Package Index (PyPI) has spread to GitHub and expanded to reach at least 100,000 compromised repositories.

According to security firm Apiiro, the campaign to poison code involves cloning legitimate repos, infecting them with malware loaders, uploading the altered files to GitHub under the same name, then forking the poisoned repo thousands of times and promoting the compromised code in forums and on social media channels.
Saw that today over at el Reg... https://www.theregister.com/2024/03/...fork_campaign/

Should be a piece of cake for the Ms AI one would perhaps think?

Otoh, saw a couple of years ago that Ms would use AI to help with Ms updates and anyone following how that circus has turned out, then perhaps not.

Secure supply chain is of utmost importance these days...

Last edited by Jan K.; 03-01-2024 at 07:48 AM. Reason: spelling... sigh
 
Old 03-04-2024, 10:46 AM   #2
Jan K.
Member
 
Registered: Apr 2019
Location: Esbjerg
Distribution: Windows 7...
Posts: 773

Original Poster
Rep: Reputation: 489Reputation: 489Reputation: 489Reputation: 489Reputation: 489
Speaking of secure supply chains... https://popey.com/blog/2024/02/exodu...-490k-swindle/
 
Old 03-25-2024, 06:50 PM   #3
Jan K.
Member
 
Registered: Apr 2019
Location: Esbjerg
Distribution: Windows 7...
Posts: 773

Original Poster
Rep: Reputation: 489Reputation: 489Reputation: 489Reputation: 489Reputation: 489
Quote:
Over 170K users caught up in poisoned Python package ruse
Interesting links and background... https://www.theregister.com/2024/03/...ckage_malware/
 
Old 03-28-2024, 03:56 PM   #4
Jan K.
Member
 
Registered: Apr 2019
Location: Esbjerg
Distribution: Windows 7...
Posts: 773

Original Poster
Rep: Reputation: 489Reputation: 489Reputation: 489Reputation: 489Reputation: 489
From the daily news...

How to use hallucinating AI to inject poisoned software into the supply chain... https://www.theregister.com/2024/03/...ware_packages/

Walled gardens under attacks are nothing new, here's snap store "After multiple waves of cryptocurrency credential-stealing apps were uploaded to the Snap store, Canonical is changing its policies." https://www.theregister.com/2024/03/...p_store_scams/



Totally unrelated, but a fun AI event https://futurism.com/the-byte/ai-pow...less-screaming
 
Old 03-28-2024, 06:04 PM   #5
rokytnji
LQ Veteran
 
Registered: Mar 2008
Location: Waaaaay out West Texas
Distribution: antiX 23, MX 23
Posts: 7,112
Blog Entries: 21

Rep: Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474Reputation: 3474
It's everywhere. Glad I run a Window Manager

https://news.itsfoss.com/kde-plasma-...-theme-fiasco/
 
1 members found this post helpful.
Old 03-30-2024, 04:56 PM   #6
Jan K.
Member
 
Registered: Apr 2019
Location: Esbjerg
Distribution: Windows 7...
Posts: 773

Original Poster
Rep: Reputation: 489Reputation: 489Reputation: 489Reputation: 489Reputation: 489
"...XZ security vulnerability due to malicious code making it into the codebase."

https://www.phoronix.com/news/XZ-CVE-2024-3094

"The resulting malicious build interferes with authentication in sshd via systemd. "


Updated:
....


"Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service. If you are the owner of the repository, you may reach out to GitHub Support for more information."

The ToS violation presumably due to the compromised upstream commit access.



https://www.phoronix.com/news/GitHub-Disables-XZ-Repo
 
Old 03-30-2024, 05:25 PM   #7
Jan K.
Member
 
Registered: Apr 2019
Location: Esbjerg
Distribution: Windows 7...
Posts: 773

Original Poster
Rep: Reputation: 489Reputation: 489Reputation: 489Reputation: 489Reputation: 489
Just came across this interesting post on the inner workings of the attacking code...

https://lwn.net/ml/oss-security/2024...3.anarazel.de/
 
1 members found this post helpful.
Old 03-30-2024, 06:16 PM   #8
Jan K.
Member
 
Registered: Apr 2019
Location: Esbjerg
Distribution: Windows 7...
Posts: 773

Original Poster
Rep: Reputation: 489Reputation: 489Reputation: 489Reputation: 489Reputation: 489
Found by chance...

"Someone put a lot of effort for this to be pretty innocent looking and decently
hidden. From binary test files used to store payload, to file carving,
substitution ciphers, and an RC4 variant implemented in AWK all done with just
standard command line tools. And all this in 3 stages of execution, and with an
"extension" system to future-proof things and not have to change the binary test
files again. I can't help but wonder (as I'm sure is the rest of our security
community) - if this was found by accident, how many things still remain
undiscovered.
"

https://lwn.net/ml/oss-security/2024...@openwall.com/

Everyone _really_ should read the entire thread.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
LXer: GitHub wants more new contributors, because that's what GitHub is for LXer Syndicated Linux News 0 07-27-2017 06:36 AM
LXer: Israeli soldiers hit in cyberespionage campaign using Android malware LXer Syndicated Linux News 0 02-18-2017 11:21 AM
LXer: Hacktoberfest campaign leads to nearly 50K GitHub contributions LXer Syndicated Linux News 0 12-04-2015 09:42 AM
LXer: Active malware campaign uses thousands of WordPress sites to infect visitors LXer Syndicated Linux News 0 09-21-2015 03:12 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:46 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration