Hacker News new | ask | show | jobs
by josefdlange 3759 days ago
Someone compromised their main web server where the binaries are hosted and put up a malicious binary.
2 comments

Do you have a citation for this? The extent of what was illicitly accessed remains unclear. Without knowing how their infrastructure is set up, it's not possible to say that the intrusion was limited to just the web server.
Here's the Reuters article where they state that:

http://www.reuters.com/article/apple-ransomware-idINL1N16F17...

Thanks for that, at least it's something. John Clay is listed here[1] as a contributor to "Website maintenance and troubleshooting, Mac OS X help documentation". I wish they would post a similar update on their website and explicitly confirm that the current source and binaries have been audited and are safe.

[1] https://github.com/jparyani/Transmission/blob/master/AUTHORS

They've probably addressed it officially by now, but the malware was only included in v2.9.0 downloaded from the web page directly. It wasn't included if the update was performed through the Transmission client. That would seem to suggest it was the web server that was compromised.
Apparently [1] the binaries are hosted on the same server as their forums.

[1] https://twitter.com/leifnixon/status/706786995029340160