April 22, 2024, 3:26 p.m. | Bruce Schneier

Schneier on Security www.schneier.com

Interesting social-engineering attack vector:


McAfee released a report on a new LUA malware loader distributed through what appeared to be a legitimate Microsoft GitHub repository for the “C++ Library Manager for Windows, Linux, and MacOS,” known as vcpkg.


The attacker is exploiting a property of GitHub: comments to a particular repo can contain files, and those files will be associated with the project in the URL.


What this means is that someone can upload malware and “attach” it …

attack attacker attack vector can comments distributed engineering exploiting files github github repository library linux loader lua macos malware manager mcafee microsoft open source property repo report repository social social engineering urls windows

Security Analyst

@ Northwestern Memorial Healthcare | Chicago, IL, United States

GRC Analyst

@ Richemont | Shelton, CT, US

Security Specialist

@ Peraton | Government Site, MD, United States

Information Assurance Security Specialist (IASS)

@ OBXtek Inc. | United States

Cyber Security Technology Analyst

@ Airbus | Bengaluru (Airbus)

Vice President, Cyber Operations Engineer

@ BlackRock | LO9-London - Drapers Gardens