Conversation
Notices
-
silverwizard (silverwizard@friendica.obscuritus.ca)'s status on Thursday, 03-Jan-2019 14:40:02 EST
silverwizard
♲ @Tabletop Scenarios (badthingsdaily@twitter.com): Happy new year.
A developer has just typo'd an upstream package installation to their laptop.
There was a malicious package waiting for that typo.
The post-installation code is exfiltrating environment variables and full directories with .git folders from that shell.