Hacker News new | ask | show | jobs
by jwilk 1420 days ago
> So far found in projects including: crypto, golang, python, js, bash, docker, k8s

Huh? What does that mean?

2 comments

The author is being obtuse. They mean that clones have been made of those projects that include malicious code.

It's like if I make a copy of the New York Times website but replace the cover image with nudity and put it on a different URL and someone tweets "omg NYT has nudity on the front page" and clarifies, vaguely, 10 tweets down that it was actually not the real NYT but a clone.

I'm not convinced that the author is spinning it this way on purpose (ie for maximum emotional effect / retweets / internet points) or if it just comes from being too close to the subject matter, but it's pretty misleading either way.

Riiight, that makes a LOT more sense. This would have been HUGE if the actual repos were infected and it wasn’t even at the top here at HN. I was very worried for a minute there, your comment has calmed me right down. Thank you!
This should be the top comment on this thread.
It appears what is infected are forks of those repos but not the originals.
What would make sense for golang, python, docker, k8s; maybe even bash if you squint a bit.

But what's the repo for "crypto" or "js"?