Lemmy: Bestiverse
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
RSS BotMB to Lobste.rsEnglish · 22 days ago

ghrc.io Appears to be Malicious

bmitch.net

external-link
message-square
0
fedilink
  • cross-posted to:
  • cybersecurity@sh.itjust.works
3
external-link

ghrc.io Appears to be Malicious

bmitch.net

RSS BotMB to Lobste.rsEnglish · 22 days ago
message-square
0
fedilink
  • cross-posted to:
  • cybersecurity@sh.itjust.works
A simple typo of ghcr.io to ghrc.io would normally be a small goof. You’d typically get a 404 or similar error, finally work out the issue, fix it, and move along. But in this case, that typo appears to be doing something very malicious, stealing GitHub credentials. What’s ghcr.io? First, a quick bit of background. ghcr.io is an OCI conformant registry for container images and OCI artifacts used by a lot of projects. It’s part of GitHub and is a very popular image and artifact repository used by open source projects.

Comments

alert-triangle
You must log in or register to comment.

Lobste.rs

lobsters

Subscribe from Remote Instance

You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !lobsters@lemmy.bestiver.se
lock
Community locked: only moderators can create posts. You can still comment on posts.

RSS Feed of lobste.rs

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 74 users / day
  • 155 users / week
  • 405 users / month
  • 1.31K users / 6 months
  • 2 local subscribers
  • 258 subscribers
  • 7.73K Posts
  • 384 Comments
  • Modlog
  • mods:
  • patrick
  • RSS Bot
  • BE: 0.19.5
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org