Is yt-dlp/yt-dlp compromised?
github.com
github.com
3f6ab524d899f39ef46004a9db1f09ac8983aa5bd96243c417edf7c0c00627d7 yt-dlp_linux 2024.11.04 dcca6afb6ac9770d4d3425c35e415f4a8fc69b626c60f12ca899bfc05f6a72fc yt-dlp_linux 2024.10.22
https://www.virustotal.com/gui/file/3f6ab524d899f39ef46004a9...
PoC Rust program that takes the contents of .npmrc and uploads it to a random IP (DONT RUN THIS! It'll steal your npm authentication token): https://gist.github.com/victorb/adf0ac8b7ada8d5a4982462e24e8...
"No security vendors flagged this file as malicious" = https://www.virustotal.com/gui/file/b99b86a5ce3aa24b39ec53dd...
But clearly, it is malicious :)
I suspect virustotal did the check in a container with a logrotation job still running, and it happened to run right in the moment when yt-dlp was being tested.
And since we're all amateurs here who don't understand what VirusTotal is doing, some of us think "ZOMG yt-dlp compromised?!?".
If you look at the process tree, the process that reloaded rsyslog wasn't spawned from the yt-dlp_linux process.
https://www.virustotal.com/gui/file/dcca6afb6ac9770d4d3425c3...
Says it contacted 45.66.35.11 and you can see its a tor relay https://metrics.torproject.org/rs.html#details/7EA6EAD6FD830...
Though haven't looked at how yt-dlp works, I'd guess yt-dlp might attempt to use tor network in case some IP or network is blocked and can't reach a server.
> @seproDev unrelated, but what you think about https://news.ycombinator.com/item?id=42040600
.. and one of the main maintainers (ranked #14th by #commits, but a recently active maintainer) replied the following: > False positive in virus total. Calling yt-dlp without any arguments makes no web requests.
> To expand a bit more. Our releases are built with github runners and they report back the sha hash during build. https://github.com/yt-dlp/yt-dlp/actions/runs/11656153929 for the release from yesterday
> You can see the commit that was built, what we merged in the last couple days, and the hash of the resulting files to check against the files in the release section.
> Those network requests are likely just other processes on the machine. I remember windows executable would regularly show microsoft servers in the "connections made" list due to windows update and telemetry still running.
[1] https://github.com/yt-dlp/yt-dlp/issues/11451#issuecomment-2...I edited my reply too.
Edit: I'd caution against spamming the maintainers though (not caution you specifically), the possibility of that happening is what swayed me to not post the link originally.
It seems like virustotal also records unrelated processes running on that host, logrotation is a normal thing.
(The second part of your comment was just normal log rotation as it turns out)
> If you see a [dead] post that shouldn't be dead, you can vouch for it. Click on its timestamp to go to its page, then click 'vouch' at the top. When enough users do this, the post is restored. There's a small karma threshold before vouch links appear.