Jump to content
The Dark Mod Forums
Sign in to follow this  
wanderer

Open Source Malware Vector

Recommended Posts

As I understand it, the target app was related to Crypto mining so the incentive to infiltrate was much higher

than with other dormant projects.

 

It's good that the alarm bell is being raised anyway.


Please visit TDM's IndieDB site and help promote the mod:

 

http://www.indiedb.com/mods/the-dark-mod

 

(Yeah, shameless promotion... but traffic is traffic folks...)

Share this post


Link to post
Share on other sites

one of the benefits of opensource is that everyone can read the code.

And there are some os projects who got and got ridden this problem.

 

But then again,

not everyone is a good coder who can detects this code.

And who is compiling the code,..

Edited by freyk

Share this post


Link to post
Share on other sites

Coders using node.js in general seem to really like to pile up a lot of dependencies - while giving a shit about devops security. Looks like shady folks stumbled upon news from 2013.
Another bad practice: Naively downloading and executing Docker images.

It is a bit like the big email worm epidemics - but for naive devs wich search and download the malware instead of naive users wich click on malware mailed to them.

 

Really wonder when we will see the first realworld Meltdown and Spectre exploits though. Does not look like anybody really cares about fixing that holes on millions of old CPUs. And some of that hardware design bugs should be exploitable by tricking a user to run JavaScript embedded on a web page or injected into it by targetted advertising...

Edited by Abusimplea

Share this post


Link to post
Share on other sites

there's malware in adverts, you see a lot if you mod minecraft, they use adfly as revenue when downloading a mod, and about 90 percent of adfly adverts are infected, so i use a adblocker, which blocks the malware infected ads, they complain that am stopping them from gaining revenue, but what revenue are they getting from an online ad site that loads there ads with malware.

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Sign in to follow this  

×
×
  • Create New...