• msfroh@lemmy.ca
    link
    fedilink
    English
    arrow-up
    2
    ·
    6 days ago

    I read the article and they mentioned that the hacker got a malicious PR merged, but didn’t link to it. Does anyone know where that PR is?

    • swicano@slrpnk.net
      link
      fedilink
      English
      arrow-up
      2
      ·
      6 days ago

      The PR, Here and the register piece with a screenshot of the file it downloads Here

      Pretty obvious “this adds code that downloads a file for some reason” stuff, and completely unrelated commit message