• just_another_person@lemmy.world
    link
    fedilink
    arrow-up
    33
    arrow-down
    2
    ·
    2 months ago

    This isn’t really a supply chain attack. It’s more social engineering: fake users, forks, and non-verified code. They’re taking advantage of the fact that most people don’t use verified releases or packages code from open source projects.

    GitHub is not compromised, nor sending unintended payloads.

    • ikidd@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      2
      ·
      2 months ago

      Many of the projects are backend dev tools, like the Atlas provider linked in the thread.

      • just_another_person@lemmy.world
        link
        fedilink
        arrow-up
        20
        ·
        edit-2
        2 months ago

        But that’s not a supply chain attack. If projects or platforms are compromised and THEN their code is used by normal means of ingestion of said project, that would be a supply chain attack.

        These are unofficial channels created as forks of existing projects in an attempt to fool users into using these instead.

  • crystalwalrus@programming.dev
    link
    fedilink
    arrow-up
    12
    ·
    2 months ago

    Another reason that star count is a terrible metric for quality / authenticity. Fake stars are a huge problem that not a lot of people take seriously.

  • Goun@lemmy.ml
    link
    fedilink
    arrow-up
    5
    ·
    2 months ago

    Why the Documents folder tho? Who expects important stuff to be there?

    Now all my Linux ISOs are gone, smh

  • Phoenixz@lemmy.ca
    link
    fedilink
    arrow-up
    4
    ·
    2 months ago

    Yay, finally Linux is being attacked!

    And as expected it takes whole lot more than clicking on an email attachment

    Always check before you curl download something!

    • CarrotsHaveEars@lemmy.ml
      link
      fedilink
      arrow-up
      2
      ·
      2 months ago

      No. Feel free to download shit and even attempt to run shit. Chances are they won’t run because shits are compiled against glibc and my system is not.