Working with maintainers (on the GitHub side) there’s definitely been a rise of malware dropper attacks against popular OSS repos, though this is particularly brazen - pressure tactics and all.
jtakkala
Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).
show comments
ncr100
Wait, who is the robot? Am I getting that right, someone in that thread is AI?
Working with maintainers (on the GitHub side) there’s definitely been a rise of malware dropper attacks against popular OSS repos, though this is particularly brazen - pressure tactics and all.
Not going to comment on the PR commentary, but the victim GitHub account is suspicious itself, recent account, a few fresh repos, following 14.5k others, and I count three surnames on the account (the username, plus two in the README history).
Wait, who is the robot? Am I getting that right, someone in that thread is AI?
holy shit