Sharing this here to get awareness for devs because Discourse might be using one of the infected repo’s…
6 „Gefällt mir“
The infected repos are clones of the originals, the originals are OK.
5 „Gefällt mir“
We’re not aware of any impact to Discourse or our dependencies.
As @Mr.X_Mr.X mentioned, the tweet author has admitted that the findings were limited to forks/clones, rather than the true versions of dependencies:
11 „Gefällt mir“
Ah that is good to know. Better safe then sorry, haha. Felt this was a place where devs at least should be aware of the malware.
3 „Gefällt mir“
Welcome to internet!
2 „Gefällt mir“