RE: https://social.lol/@otaviocc/116076383907156741
I have no words to thank everyone for helping yesterday.
Great news: Yesterday on the omg.lol IRC server, folks investigated and discovered the GitHub account was part of a network of bots. These bots republish open source projects, modifying their READMEs with malicious links, and distribute Windows malware through fake builds.
After documenting the findings, we reported everything to GitHub. Within hours, they took down the repositories and an account for violating their Terms and Code of Conduct.
Thank you for investigating, reporting, and sending coffee. You're all amazing!
I planned to write a blog post today, but
@brennanBrennan Kenneth Brown already wrote something better than I could. You should read it:
https://brennan.day/the-curious-case-of-the-triton-malware-fork/
Many thanks to
@brennanBrennan Kenneth Brown,
@chilliChilli
,
@adamAdam Newbold
, mattl,
@cygnoir,
@annikaAnnika Backstrom,
@jarunmbmb
, and everyone else who helped!
#OpenSource #macOSDev #omglol #GitHub