• stevedidwhat_infosec@infosec.pub
      link
      fedilink
      arrow-up
      0
      ·
      5 months ago

      This has almost nothing to do with what you’re talking about.

      A Chinese company bought the domain and the service in February and are attacking people in highly specific conditions. (Mobile devices at specific times)

      This is an attack. Not negligence, not an uh oh oopsie woopsie fucky wucky. Attack.

        • stevedidwhat_infosec@infosec.pub
          link
          fedilink
          arrow-up
          0
          ·
          5 months ago

          … he made plenty off the product and made additional when he sold. Devs ability to make money has nothing to do with companies coming in and injecting malware to the service.

          Any threat actor group with sufficient funds from various campaigns, spyware, etc could use said funds to buy out a dev, owner, etc.

          Not to mention state-sponsored threat actors. This is the perfect example of distracting from the fact of what happened.

          • onlinepersona@programming.dev
            link
            fedilink
            English
            arrow-up
            0
            ·
            5 months ago

            You don’t believe that income (or lack thereof) can motivate the sale of a popular library to a shady party?

            Any threat actor group with sufficient funds from various campaigns, spyware, etc could use said funds to buy out a dev, owner, etc.

            I don’t see VLC being bought out.

            This is the perfect example of distracting from the fact of what happened.

            If you say so… this isn’t the first time an underpaid opensource dev sold their project only for it to end up being used for ads or malware.

            Anti Commercial-AI license

  • stevedidwhat_infosec@infosec.pub
    link
    fedilink
    arrow-up
    0
    ·
    edit-2
    5 months ago

    For anyone interested - I’d you are using umatrix to block shit you can punch these lines into a new text file and import as blocklist, then commit it with the tiny arrow that points left toward the permanent list to save it permanently:

    * www[.]googie-anaiytics[.]com * block

    * kuurza[.]com * block

    * cdn[.]polyfill[.]io * block

    * polyfill[.]io * block

    * bootcss[.]com * block

    * bootcdn[.]net * block

    * staticfile[.]org * block

    * polyfill[.]com * block

    Remove the square brackets before saving the file - these are here to prevent hyperlinks and misclicks.

    Edit: this is not a bulleted list, every line must start with an asterisk, just in case your instance doesn’t update edits made to comments quickly.

    Edit2: added new IOCs