Gentoo Archives: gentoo-user

From: "Francisco Blas Izquierdo Riera (klondike)" <klondike@g.o>
To: gentoo-user@l.g.o
Subject: Re: [gentoo-user] Re: Hostile takeover of our github mirror. Don't use ebuild from there until new warning!
Date: Fri, 29 Jun 2018 01:12:39
Message-Id: 60cf0b2c-227a-eb1c-076c-c2946ef6ebd5@gentoo.org
In Reply to: Re: [gentoo-user] Re: Hostile takeover of our github mirror. Don't use ebuild from there until new warning! by Mick
1 El 29/06/18 a las 00:27, Mick escribió:
2 > On Thursday, 28 June 2018 22:54:45 BST Francisco Blas Izquierdo Riera
3 > (klondike) wrote:
4 >> El 28/06/18 a las 23:15, Francisco Blas Izquierdo Riera (klondike) escribió:
5 >>> Hi!
6 >>>
7 >>> I just want to notify that an attacker has taken control of the Gentoo
8 >>> organization in Github and has among other things replaced the portage
9 >>> and musl-dev trees with malicious versions of the ebuilds intended to
10 >>> try removing all of your files.
11 >>>
12 >>> Whilst the malicious code shouldn't work as is and GitHub has now
13 >>> removed the organization, please don't use any ebuild from the GitHub
14 >>> mirror ontained before 28/06/2018, 18:00 GMT until new warning.
15 >>>
16 >>> Sincerely,
17 >>> Francisco Blas Izquierdo Riera (klondike)
18 >>> Gentoo developer.
19 >> Just to keep up with it. There is a more complete article published at
20 >> https://www.gentoo.org/news/2018/06/28/Github-gentoo-org-hacked.html
21 > Thanks for letting us know, but how did this happen?
22 I don't think there is an official timeline yet. We suspect the github
23 account of an administrator was compromissed.
24
25 I just brought up the heads up when I noticed that the protage tree had
26 been modified to contain harmful code.

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies