Hacker News new | past | comments | ask | show | jobs | submit login
JFrog research discovers coordinated attacks on Docker Hub that planted millions (jfrog.com)
47 points by based2 24 days ago | hide | past | favorite | 4 comments



Interesting excerpt from the article:

excludeGeoTargeting contains codes of countries where the malware shouldn’t be installed

"excludeGeoTargeting": [ "RU", "AZ", "AM", "BY", ]


Very common in malware. They avoid their own country and close allies to be a lower priority for investigators.


Also why it’s (maybe? ) not a bad idea to configure russian as a language on your system. Some malware looks for language as well as regional configurations


Posting a README with spam or a link to malware is not particularly sophisticated, especially given that Docker Hub literally serves executables that people download and run without any vetting. It would be very easy to find a popular open source project that isn’t containerized and publish an image that contains malware, and convince users to run with —-privileged or —-network=host which are already to most users magical flags they don’t understand.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: