Hacker News new | past | comments | ask | show | jobs | submit login

Out of curiosity I looked at the list of followers of the account who committed the backdoor.

Randomly picked https://github.com/Neustradamus and looked at all their contributions.

Interestingly enough, they got Microsoft to upgrade ([0],[1]) `vcpkg` to liblzma 5.6.0 3 weeks ago.

[0] https://github.com/microsoft/vcpkg/issues/37197

[1] https://github.com/microsoft/vcpkg/pull/37199




OMG: look at the other contributions. He is trying to take over projects and pushing some change to sha256 in a hundred projects.

Example: https://github.com/duesee/imap-flow/issues/96


This guy's interactions seem weird but it might just be because of the non-native english or a strange attitude, or he's very good at covering his track e.g. found a cpython issue where he got reprimanded for serially opening issues: https://github.com/python/cpython/issues/115195#issuecomment...

But clicking around he seems to mostly be interacting with interest around these bits e.g. https://github.com/python/cpython/issues/95341#issuecomment-... or pinging the entire python team to link to the PR... of a core python developer: https://github.com/python/cpython/issues/95341#issuecomment-...

If I saw that on a $dayjob project I'd pit him as an innocuous pain in the ass (overly excited, noisy, dickriding).

Here's a PR from 2020 where he recommends / requests the addition of SCRAM to an SMTP client: https://github.com/marlam/msmtp/issues/36 which is basically the same thing as the PR you found. The linked documents seem genuine, and SCRAM is an actual challenge/response authentication method for a variety of protocols (in this case mostly SMTP, IMAP, and XMPP): https://en.wikipedia.org/wiki/Salted_Challenge_Response_Auth...

Although, and that's a bit creepy, he shows up in the edition history for the SCRAM page, the edit mostly seem innocent though he does plug his "state of play" github repository.


> dickriding

https://www.urbandictionary.com/define.php?term=Dickriding

I guess I'm not in the right demographic to know the term.


"fawning" or "ingratiating" seem to be the standard English words for this.


True, it does seem innocent enough upon more reflection.


What? They're just asking for some features there?

Ya'll need to calm down; this is getting silly. Half the GitHub accounts look "suspicious" if you start scrutinizing everything down the the microscopic detail.


I appreciate the way that duesee handled that whole issue.


reported the account to github, just in case.


Hey, I remember this guy! Buddy of someone who tried to get a bunch of low quality stuff into ifupdown-ng, including copying code with an incompatible license and removing the notice. He's in every PR, complaining the "project is dead". He even pushes for the account to be made "team member".

https://github.com/ifupdown-ng/ifupdown-ng/pulls/easynetdev

He follows 54k accounts though, so it may indeed just be coincidence.


The PR + angry user pushing for the PR author to gain commit access spiel is definitely suspiciously similar to what happened with xz-utils. Possible coincidence but worth investigating further.


I wouldn't be surprised if that is just a bot.

He even follows me, though I have never published any open-source project on my own.


Dear @0xthr0w4, do you attack me because I have requested the XZ update?

Do not mix, I am not linked to the XZ project.


The parent comment doesn't read like an attack to me. Just an observation. Would be curious why you wanted the update though.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: