VOGONS


First post, by UCyborg

User metadata
Rank Oldbie
Rank
Oldbie

I reported this repo almost 3 weeks ago, but still nothing.

Arthur Schopenhauer wrote:

A man can be himself only so long as he is alone; and if he does not love solitude, he will not love freedom; for it is only when he is alone that he is really free.

Reply 1 of 5, by twiz11

User metadata
Rank Oldbie
Rank
Oldbie

[quote=UCyborg post_id=1421341 time=1778269743 user_id=31848]
I reported [url=https://github.com/akutayo2/GPlayApiCli]this repo[/url] almost 3 weeks ago, but still nothing.
[/quote]

github is owned by the biggest malware of em all, microsoft

Reply 2 of 5, by Robbbert

User metadata
Rank Member
Rank
Member

How do you know it's malware?

Reply 3 of 5, by RandomStranger

User metadata
Rank Oldbie
Rank
Oldbie

I was thinking the same. Circumventing Google's user identification/authentication might break their terms of service, but not malicious on its own.

sreq.png retrogamer-s.png

Reply 4 of 5, by jmarsh

User metadata
Rank Oldbie
Rank
Oldbie

The user in question has forked the repository and then the only change was to replace the release download. So yes, there's a good chance they've infected it with malware.

Reply 5 of 5, by UCyborg

User metadata
Rank Oldbie
Rank
Oldbie

https://www.virustotal.com/gui/file/3f22e6637 … ed68148f483c545

Somehow, the only reason it ended up on VirusTotal, is me. 😀

Arbitrary ZIP inserted into the source tree, the malicious author force-pushes the same commit multiple times a day to inflate his contribution count, a legitimate developer would totally do that. /s

Repo was published as new, bypassing fork function (valid way to go in some cases, but the ill-intent in this case), readme changed to direct user to the malicious payload, the ZIP itself contains Lua interpreter, obfuscated script and a CMD to invoke Lua interpreter to execute the script. The script silently generates additional executables and installs scheduled tasks to run them.

That report on VirusTotal is not complete, it doesn't answer the question what generated executables do.

And that POS appears on top on popular search engines while the legitimate repo is hidden from plain sight. 😠 Though I haven't figured out Gradle / Java to get it to run...

Arthur Schopenhauer wrote:

A man can be himself only so long as he is alone; and if he does not love solitude, he will not love freedom; for it is only when he is alone that he is really free.