Stephen Lacy Profile picture
Cryptography. Infrastructure. Open source. Building infrastructure startup. https://t.co/DUXI53rhv4 Built @staehere @playgodfall
Aug 3, 2022 14 tweets 5 min read
I am uncovering what seems to be a massive widespread malware attack on @github.

- Currently over 35k repositories are infected
- So far found in projects including: crypto, golang, python, js, bash, docker, k8s
- It is added to npm scripts, docker images and install docs Most of these commits seem to be innocuous, with messages such as "bump version to 0.3.11"
github.com/operatino/roni…