Log in

View Full Version : WARNING: FossHub compromised with malware droppers


LigH
3rd August 2016, 15:28
According to their Twitter account (https://twitter.com/CultOfRazer), the "Pegglecrew" hacked FossHub (currently shut down) and replaced installers of several freeware tools (Classic Shell, Audacity) with malware droppers, which are reported to replace the MBR with a death message. They say an EFI module was ready but not included due to issues with the installer...

The MBR may be restored e.g. with the known repair feature of Windows installation disks, but an additional scan from antivirus boot disks will be recommended.

via heise News (http://www.heise.de/newsticker/meldung/FossHub-kompromittiert-Software-Installer-mit-Malware-infiziert-3286347.html) (German) - via Reddit (https://www.reddit.com/r/pcmasterrace/comments/4vw21h/massive_psa_do_not_download_classic_shell_read/)

Nevilne
3rd August 2016, 16:50
Pretty insane for a download site to get pwned in 2016.
At least sourceforge included malware in installers because they were simply evil and wanted to, lol.

The hack itself is quite harmless btw, could have been much worse.

Groucho2004
3rd August 2016, 17:17
Theoretically, "fdisk /mbr" should still work and fix the MBR. Then again, nowadays there are probably modern tools out there that do that.

Fullmetal Encoder
3rd August 2016, 23:13
In case anyone who sees this thread is wondering about it, the MKVToolnix link doesn't appear to have been infected. I downloaded it yesterday and it seemed to install normally and I was able boot up just fine today.

kuchikirukia
6th August 2016, 11:44
It was. It was a 35KB exe so it was pretty obvious. qBittorrent was the same.