https://www.virustotal.com/gui/file/3f6ab524d899f39ef46004a9...
https://www.virustotal.com/gui/file/3f6ab524d899f39ef46004a9...
PoC Rust program that takes the contents of .npmrc and uploads it to a random IP (DONT RUN THIS! It'll steal your npm authentication token): https://gist.github.com/victorb/adf0ac8b7ada8d5a4982462e24e8...
"No security vendors flagged this file as malicious" = https://www.virustotal.com/gui/file/b99b86a5ce3aa24b39ec53dd...
But clearly, it is malicious :)
https://www.virustotal.com/gui/file/dcca6afb6ac9770d4d3425c3...
Says it contacted 45.66.35.11 and you can see its a tor relay https://metrics.torproject.org/rs.html#details/7EA6EAD6FD830...
Though haven't looked at how yt-dlp works, I'd guess yt-dlp might attempt to use tor network in case some IP or network is blocked and can't reach a server.
I suspect virustotal did the check in a container with a logrotation job still running, and it happened to run right in the moment when yt-dlp was being tested.
And since we're all amateurs here who don't understand what VirusTotal is doing, some of us think "ZOMG yt-dlp compromised?!?".
If you look at the process tree, the process that reloaded rsyslog wasn't spawned from the yt-dlp_linux process.