|
|
|
|
|
by oefrha
1420 days ago
|
|
What a garbage clickbait thread. From scary words like "attack", "infected", etc. you would think projects are compromised. But nothing is compromised. From wayyyyy down in the thread: > The attacker creates FAKE orgs/repos and pushes clones of LEGIT projects to github. Yeah, anyone can push anything to their own GitHub accounts/orgs, including malware. We know that. Save yourself some time. Flagged. |
|
It's absolutely true that the wording is wrong, but I think it's reasonable to accept a jumped the gun rather than a clickbait explanation.
The presence of large volumes of project copies on typosquats and synonym squats is still a problem, they'll still get indexed by tools, and then the tools boost their page rank, and eventually some make it to users. Given that the Go init payload contains an RCE and not just a data collection, there is still something of note there. Yes it's not 35k compromised projects, but it is a broad deployment of malicious code.