Hacker News new | ask | show | jobs
by 3np 1420 days ago
TL;DR: These are forks by unknown people containing malware. I see no indication in the linked thread of even a single successful compromise actually occurring, or malicious code making it into legitimate upstream projects.
1 comments

Here is a commit with malicious code from a Microsoft employee:

https://github.com/promonlogicalis/asn1/commit/7bdca06d0edf8...

That commit was rewritten from https://github.com/Logicalis/asn1/commit/d60463189a563e49f19... which was signed, but is not in the fork.
Damn, github should show some big visible warning about this.
As long as the commit is not signed (marked green), that means nothing.
This is interesting. If you go to that user's profile, and look at the "contributions", there are none in July / August. Yet the commit is from two days ago.