Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It looks like an earlier commit with a binary blob "test data" contained the bulk of the backdoor, then the configure script enabled it, and then later commits patched up valgrind errors caused by the backdoor. See the commit links in the "Compromised Repository" section.

Also, seems like the same user who made these changes are still submitting changes to various repositories as of a few days ago. Maybe these projects need to temporarily stop accepting commits until further review is done?



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: