Remix.run Logo
▲ packeted 2 hours ago

Great initiative. I recently got stung by an advert on reddit for "HBO Max for MacOS, 6 months free" from the official HBO user (don't get me started on how that slipped through). Front and center was a curl | bash copy to clipboard that obfuscated the payload source in base10. I knew better, but I think we've made this kind of thing way too acceptable. Of course it was malware and I realized the instant I pressed enter. Thankfully I didn't give it my password and immediately disconnected from the internet and killed the machine. I'm genuinely concerned these kind of attacks are going to become much more commonplace with AI, plus the ability to inject malicious code in to things that get run by trusted scripted installers.

▲andelink 2 hours ago | parent | next [-]

You curled and executed bash code allegedly from _HBO_?

▲swozey 2 hours ago | parent | prev [-]

They all dump env and ship it off so check for any keys you might have had in there if anything was able to send at all.