Hacker News new | ask | show | jobs
by brcmthrowaway 410 days ago
Ultimately, does this require installing a sketchy app in the first place?
3 comments

Lots of credible apps use lots of dependencies. Find an abandoned one, get your code into it, …
Or a reputable one with that line of code included (in one of the updates, after having built a good reputation); maybe dormant until a certain date.
Or a bug in some good app that allows an attacker to execute the right thing.
Yes.