Closed machinly closed 1 year ago
How the heck did you became aware of this?
How the heck did you became aware of this?
I was running the benchmark in an environment without wifi and it waited a long time after launching, so I looked into it and found it all.
This PR replace the malicious version of
github.com/tockins/fresh
.The new version (
v0.0.0-20220719194346-eee4eda4271e
) ofgithub.com/tockins/fresh
have malicious code ininit
func of every go file. And you can't see this version in github.After
make build
, You can find that in~/go/pkg/mod/github.com/tockins/fresh@v0.0.0-20220719194346-eee4eda4271e
. And The malicious code looks like this. It's post env to the weird url.