Hacker News new | ask | show | jobs
by prokoudine 4039 days ago
http://sourceforge.net/u/sf-editor1/profile/

Nice list. Got Audacity there, for instance.

4 comments

Several of those are projects that were never hosted at SourceForge, aren't they? Firefox, for example, I don't believe was ever an SF project. WordPress, I don't recall ever seeing on SourceForge. Are they altering the binaries they are posting on their "mirror"?

This is very confusing.

Bitcoin is on there also. Now that is worrying.
It doesn't neccessarily mean all of them are affected, but I think it's a call for a close inspection.
I download the bitcoin .exe, and it came clean, with the right signatures, but who knows how they are distributing the stuff. I have a Ubuntu computer. If they're at least a bit smart they will use their download redirects to serve the spyware only to Windows computers or something, so that could be why I got a clean binary. Bitcoin devs investigated, at my request. They removed the sf-editor1 user from the project owners and checked the binaries to see if sigs matched, and they did. But like I said, they could be filtering who they serve the "spyware" to.
Firefox, cgminer, zotero, etc.. Yikes.
These are all affected repos ! Damn !!!