• Nino477@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Tru. With Windows defender 💪 i can downloat evry .exe from ze internetz. I currently installing Gta 6 early 😎

    • sylver_dragon@lemmy.world
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      I tried that, I ended up with this weird “Windows 11” adware installed and couldn’t get rid of it. There was also a problem with odd programs and advertising showing up in my Start Menu, even after I removed them. Also, my settings would occasionally just change, without my knowledge or permission.

  • just_another_person@lemmy.world
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    This isn’t really a supply chain attack. It’s more social engineering: fake users, forks, and non-verified code. They’re taking advantage of the fact that most people don’t use verified releases or packages code from open source projects.

    GitHub is not compromised, nor sending unintended payloads.

    • ikidd@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      0
      ·
      1 month ago

      Many of the projects are backend dev tools, like the Atlas provider linked in the thread.

      • just_another_person@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 month ago

        But that’s not a supply chain attack. If projects or platforms are compromised and THEN their code is used by normal means of ingestion of said project, that would be a supply chain attack.

        These are unofficial channels created as forks of existing projects in an attempt to fool users into using these instead.

    • harsh3466@lemmy.ml
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Hahaha. Was about to comment nearly the same thing. My NFS share has a different mount. ~/Documents is an empty directory

  • crystalwalrus@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Another reason that star count is a terrible metric for quality / authenticity. Fake stars are a huge problem that not a lot of people take seriously.

      • oo1@lemmings.world
        link
        fedilink
        English
        arrow-up
        0
        ·
        1 month ago

        oh oh, I’m a below average arch user. I suspect i copied most of my hoome from debian or something.

        I’ll rename it to Dickuments as a security feature.

  • MangoPenguin@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    It’s an interesting thing to think about, wouldn’t widespread desktop Linux malware be quite bad because of the lack of any AV/Malware detection typically used?

    • just_another_person@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Uhhhhh, there’s plenty of that being used. From the ground up. Security scanning out the wazzzz. Those are pattern-based scanners though, and this probably wouldn’t be detected because it’s a blob of binary junk with a script inside. GitHub should honestly put something on their storage backends to warn users, but that’s a whole ball of wax people probably don’t want to get into.

  • Phoenixz@lemmy.ca
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Yay, finally Linux is being attacked!

    And as expected it takes whole lot more than clicking on an email attachment

    Always check before you curl download something!

  • Goun@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    Why the Documents folder tho? Who expects important stuff to be there?

    Now all my Linux ISOs are gone, smh