bmatzelle / gow

Unix command line utilities installer for Windows.
https://github.com/bmatzelle/gow/wiki
6.55k stars 363 forks source link

malicious download links being inserted into wiki home page #268

Closed dalehagglund closed 2 years ago

dalehagglund commented 2 years ago

It doesn't look like anyone's looking at these issues, but ...

The wiki home page (https://github.com/bmatzelle/gow/wiki) is world-editable, or at least it seems editable to any random person logged into github, and some unfriendly random person is changing the main "Download Installer" link to point to a malware installer.

I got hit by it a couple hours ago, and just finished getting off my laptop. I didn't get a specific name, but it was sort of spyware / keylogger, at least from what Norton told me.

From looking briefly at the history, several user names have been involved since at least October 16, 2021. It looks to me like most of the changes are given the description "Updated Home (markdown)" although that was also used before the first malicious edit I noticed.

bmatzelle commented 2 years ago

Thanks! I closed the wiki's from being world-editable.