- cross-posted to:
- opensource@programming.dev
- cross-posted to:
- opensource@programming.dev
Suspected China-state hackers used update infrastructure to deliver backdoored version.
Suspected China-state hackers used update infrastructure to deliver backdoored version.
This doesn’t seem like this is an attack that should work.
How did this bypass signature verification, sure you can send a malicious update… but unless you have the package maintainer’s private keys you can’t sign it so it would be thrown out by the package manager?
Oh, it’s Windows software.