Gentoo Archives: gentoo-user

From: Mick <michaelkintzios@×××××.com>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Hostile takeover of our github mirror. Don't use ebuild from there until new warning!
Date: Thu, 28 Jun 2018 22:27:21
Message-Id: 3474276.TakXSP8LEc@dell_xps
In Reply to: [gentoo-user] Re: Hostile takeover of our github mirror. Don't use ebuild from there until new warning! by "Francisco Blas Izquierdo Riera (klondike)"
1 On Thursday, 28 June 2018 22:54:45 BST Francisco Blas Izquierdo Riera
2 (klondike) wrote:
3 > El 28/06/18 a las 23:15, Francisco Blas Izquierdo Riera (klondike) escribió:
4 > > Hi!
5 > >
6 > > I just want to notify that an attacker has taken control of the Gentoo
7 > > organization in Github and has among other things replaced the portage
8 > > and musl-dev trees with malicious versions of the ebuilds intended to
9 > > try removing all of your files.
10 > >
11 > > Whilst the malicious code shouldn't work as is and GitHub has now
12 > > removed the organization, please don't use any ebuild from the GitHub
13 > > mirror ontained before 28/06/2018, 18:00 GMT until new warning.
14 > >
15 > > Sincerely,
16 > > Francisco Blas Izquierdo Riera (klondike)
17 > > Gentoo developer.
18 >
19 > Just to keep up with it. There is a more complete article published at
20 > https://www.gentoo.org/news/2018/06/28/Github-gentoo-org-hacked.html
21
22 Thanks for letting us know, but how did this happen?
23
24 --
25 Regards,
26 Mick

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-user] Re: Hostile takeover of our github mirror. Don't use ebuild from there until new warning! "Francisco Blas Izquierdo Riera (klondike)" <klondike@g.o>