On August 7th, Vhyrro messaged me after noticing someone had uploaded malicious rockspecs, `bcrcewon-1.0.rockspec` and `7e0b94029db0`, to luarocks.org. I suggested we notify you and Hisham and gave him Hisham's e-mail address (which I had in my address book, since I had been in touch with him before and based on prior experience knew you were hard to reach). Vhyrro found your Gmail address and sent you an email on August 7th:
--- > I've noticed that somebody on luarocks.org has uploaded two potentially malicious rockspecs: [...] These two packages contain luajit bytecode instead of traditional Lua code, which means they could contain some sort of sandbox escape and could have done some damage on the actual server itself, and may be worth investigating. Coincidentally, I've been researching this exploit vector myself over the past week, but in isolation and on my local docker run of luarocks-site. It's entirely plausible that luajit bytecode has some out-of-bounds read or write which could spell trouble for the real site, which is why I am writing you with such concern. I haven't dissected the bytecode yet, and so I can't test if it works, but it might be worth preemptively rolling out a fix. Maybe a check that disallows bytecode uploads? Seeing someone attempt a similar thing on the main luarocks site is not good news, so I recommend having a look on the main server to see if anything got compromised. ---
On August 14th, Vhyrro told me he had achieved full RCE (reproduced locally on his docker instance). He spent the next day cleaning up his POC to make it consistently reproducible. On August 15th, he sent you a second follow-up email to your Gmail address. We agreed to wait for a response for 2 weeks and then look for alternate channels to reach you on. On August 16th, he told me he was considering messaging Hisham because his previous email to you about the guy pentesting your site had gone unanswered. A day later, Vhyrro again asked me if we should try reaching out to you on other channels. I urged him to give it some time because we know you & Hisham maintain LuaRocks in your free time, and we don't want to contribute to FOSS maintainer burnout.
On August 20th, we joined the official luarocks matrix room (#luarocks_luarocks:gitter.im) and found your personal Matrix handle. That's when Vhyrro DM'd you on Matrix.
Finally, on September 10th, over a month after his initial warning about the live attack and weeks after his follow-ups regarding the RCE PoC, having received no response across email or Matrix, Vhyrro submitted the report to CERT/CC.
Regarding your comment on Lux: Dismissing our work as LLM "vibe coding" (it's not) and claiming we acted out of self-interest is an unfair personal attack. We did all we could to try and warn you early while giving you enough time to address a severe issue without causing unnecessary panic.