Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Password-stealing Linux malware served for 3 years and no one noticed (arstechnica.com)
72 points by ale42 on Sept 13, 2023 | hide | past | favorite | 9 comments


Both the Ars Technica and securelist.com articles say "Debian", with no mention of "Ubuntu".

Given how much Ubuntu has ridden atop the shoulders of Debian, without much acknowledging it, it's a shame that "password-stealing Linux malware" is labeled as involving "Debian".

Would be nice to have numbers on how much each distro ended up infected.


The ars article says “debian package”, which is a file format. It doesn’t mention any distributions.



Yup, was posted earlier


Is anyone surprised a file called "free download manager" was malware? Anyone that lived through Kazaa isn't surprised :)


It's a supply chain attack.


Obviously someone noticed, or else there wouldn't be an article.


Title says it took 3 years..


It's just a classic mathematician's answer: https://tvtropes.org/pmwiki/pmwiki.php/Main/MathematiciansAn...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: