Mantine-datatable (and others) compromised – owner account suspended
Posted by justsomehuman 4 days ago
Comments
Comment by jerf 4 days ago
Greater HN collective, please help me metaphorically double-click on this. I've poked around a bit but didn't find out much more than the given link. What are we concerned about the hack possibly having accomplished?
Because stealing repos is bad enough... but are we saying it's possible that commits can now magically appear in repos from hackers? I don't want to raise any alarms if I'm misreading this or if we're early in the news cycle, but if that's possible, I and a lot of other people reading this need to have some immediate conversations with a lot of people. So... is that what this is saying? Or am I misreading it? I sure hope so.
Comment by zuzululu 4 days ago
meanwhile the gitea running on my metalbox for nearly a decade has seen no compromise and 100% uptime when cloudflare has gone down repeatedly
im rethinking the whole "go where crowd is" , while great from evolutionary point of view, its the complete opposite. Where the crowd gathers online is the most dangerous place.
Comment by em-bee 4 days ago
Comment by LoganDark 4 days ago
Comment by em-bee 4 days ago
Comment by cookiengineer 4 days ago
Simple as that, because that's the attack surface.
https://cookie.engineer/weblog/articles/malware-insights-git...
I wrote that article December 2024. Still ongoing, Microsoft. Best enterprise security practices, I suppose shrugs ...
Comment by j1elo 4 days ago
* GitHub's backwards priorities end up causing a hack on their systems.
* Hackers use their newly gained powers to compromise other people's repos.
* GitHub dectects compromised repo, and suspends the account of its maintainer, so they cannot warn nor act against it to protect or at least warn their community of users.
"I cause a fire, and later ban you for getting burned."
No wonder people are leaving.
Comment by zuzululu 4 days ago
Comment by crazysim 4 days ago
I had a repo with more than a dozen forks banned on GitHub for some unclear TOS violations. Ticket has been sitting for a week plus now, asking for clarification and guidance.
So, it lives in codeberg now. https://codeberg.org/nelsonjchen/op-replay-clipper
Comment by zuzululu 4 days ago
Comment by crazysim 4 days ago
Comment by zuzululu 4 days ago
Comment by throawayonthe 4 days ago
Comment by arealaccount 4 days ago
Comment by dwedge 4 days ago
Two weeks later it had spammed 50GB of logs to the disk and was idling at 11GB RAM. With zero repos and zero active users. I don't want a git interface to be full of bloat.
That's why I don't like it. I'm moving a client from gitlab to forgejo at the moment.
Comment by parliament32 4 days ago
Comment by selfhoster1312 4 days ago
On the server side, gitlab was always very hard to selfhost with many moving parts, many requirements, and using much resources. gitlab-runner is not very explicit about things when you're not in the happy path (why is it not picking up jobs?).
I'm not even a minimalist. I've been running gitea/forgejo for the past 8 years or so and it's been a miracle in comparison: lightweight server, easy setup/upgrades, and super simpler UI/UX that everybody understands on the first try. Forgejo (gitea community fork) learns from everything that Github historically made good (UX) without any enshitiffication in sight (developed by a non-profit). I highly recommend it.
Comment by plagiarist 4 days ago
Comment by stronglikedan 4 days ago
Comment by phoronixrly 4 days ago
Comment by christeamrs 4 days ago
Our tool already discovers infected repositories and mitigates/removes the implants from the filesystem.
Please revoke/rotate all your tokens and passwords that were used in the infected repositories, the worm is pretty sophisticated.
Comment by Carbonhell 4 days ago
Comment by tom1337 4 days ago
Comment by rurban 3 days ago
Comment by icflorescu 3 days ago
Comment by icflorescu 3 days ago
Comment by dividendflow 4 days ago
Comment by wewewedxfgdf 4 days ago
Comment by rcxdude 3 days ago
Comment by mbreese 4 days ago
I’m thinking of it this way - if your spouse’s GH account was breached and blocked, would you let them use your account? I would not… This isn’t her account issue, it’s his.