Elektrine lite

← Feed

@ysf@chaos.social

Post #4251091

2026-07-30 19:29 UTC

@ifin@infosec.exchange @jti42@infosec.exchange @sodiboo@gaysex.cloud I only had the malware sample of the openconnect pkg. If you point me to others, I should be pretty quick with reversing the keys if it used the same obfuscation. If it is i can share the binja script.

Replies (2)

  • @jti42@infosec.exchange 2026-07-30 19:35

    @ysf@chaos.social @ifin@infosec.exchange @sodiboo@gaysex.cloud the guy who made a quick online-repo scanner found one more, see here: https://github.com/lenucksi/aur-malware-check/issues/52#issuecomment-5135221988 Also: @archlinux@fosstodon.org can you please un-429 the guys scanner it might actually do more good than harm at the current point in time.

    Open ##4251090

  • @ifin@infosec.exchange 2026-07-30 20:25

    @ysf@chaos.social @jti42@infosec.exchange @sodiboo@gaysex.cloud The nnn-nerd package appears to be the same stager. Did you have the Tor address from your samples? It'd be good to compare.

    Open ##4252514