Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

MALWARE #2031

Closed
daniel19256 opened this issue May 5, 2024 · 6 comments
Closed

MALWARE #2031

daniel19256 opened this issue May 5, 2024 · 6 comments
Labels

Comments

@daniel19256
Copy link

Installs a chrome add-on that can't be removed via conventional means (added by your "administrator") in attempts to steal data. The add-on had access to valuable data such as financial information and I would not have realised if it wasn't for the person who made this not realising that it changes your search engine to bing. Please educate me on how to report a github project.

@ArjixWasTaken
Copy link
Collaborator

ArjixWasTaken commented May 5, 2024

what? (excuse my baffled response)

I am one of the contributors and I can assure you there is no malware in our code.
But I am going to give you the benefit of the doubt, since it is possible that an npm dependency is infected, or that the automated pipeline for the releases is infected (?).

But, even with those possibilities in mind, correlation does not imply causation, so w/o further information I can't do much.
How are you 100% sure that th-ch/youtube-music is responsible for the chrome extension being installed?
And did you test this in a sandboxed environment to reach such a conclusion?

@ArjixWasTaken
Copy link
Collaborator

And also, where did you download th-ch/youtube-music from?
It is quite usual for people to create fake websites that claim to be the official website of the project, and provide a virus instead.

The only official website for this project is https://th-ch.github.io/youtube-music, any other site that claims to be official is lying to you.

@ArjixWasTaken
Copy link
Collaborator

PS: If you don't mind, can you share the exe you used to install th-ch/youtube-music?
I'd like to give it a look myself

@ArjixWasTaken ArjixWasTaken added the awaiting-reply Awaiting reply label May 5, 2024
@ArjixWasTaken
Copy link
Collaborator

ArjixWasTaken commented May 5, 2024

PS2:

It is highly likely that you are talking about a similar project Youtube Music Desktop which was taken down from github because one of the maintainers got their account compromised.

Here is a statement from one of their maintainers, Alipoodle.
And here was their repository before it got deleted.

Chances are, you downloaded the infected release from that project.

@ArjixWasTaken
Copy link
Collaborator

ArjixWasTaken commented May 5, 2024

@Alipoodle

Are you aware if that infected release forcibly installed a chrome extension to steal user data?
Although, that doesn't really sound like a great move, since one can steal data w/o a chrome extension...so I am having my doubts

Also, I see you still haven't got the org and repos back 😔

@Alipoodle
Copy link

Regarding the issue for YTM Desktop (ytmdesktop/ytmdesktop and not this project)
We can't sadly provide much information regarding the actual executable which was given as a replacement during the 7 possible hours of it being live... 😅

The information regarding it, and the 3 accounts we found associated with it all (Adler, and 2x accounts used for hosting said viruses) were all taken down prior to any of us having noticed. The project was as well taken down in this sweep.

We have obviously only just recently provided new versions of our one on a Fork, and until now we've specifically said we aren't providing a download except from KNOWN sources (GitHub from the org) and have been VERY clear with the Fork one about GPG signing and the GH Actions making the release.

@JellyBrick JellyBrick closed this as not planned Won't fix, can't repro, duplicate, stale May 24, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

4 participants