Skip to content

Comment on GitHub flooded with malware repos spoofing real projects–no response from GitHub

Comments

At this point, I’m out of ideas. Has anyone else dealt with this? How do we get GitHub to take this seriously?

Not read any thriller / conspiracy novels? :-) The way is to do exactly what you're doing here: take the news public. Very public. The more the merrier. Post to HN, LinkedIn, Facebook, Slashdot, Twitter, TikTok, Reddit, etc. Send email to every news/media outlet you can find contact info for. @mention people who work for CNN, MSNBC, ABC News, Fox News, CBS News, Reuters, Associated Press, etc. on Twitter, or find them on LinkedIn and message them. Write up a press release and submit using PRNewsWire and such-like. Record a video and post on Youtube. Contact the Attorneys General for all 50 US states. And so on.

Thanks, I just find it wild that Microsoft appears wholly uninterested in policing what seems like a huge legal liability to their business. I’ll start reaching out to as many journalists as I can with what I’ve got. They seem a little overwhelmed from the two I’ve already reached out to.

Edited to add: I’ve also been hoping that I could avoid giving the attackers too much of a heads up, but at this point the risk is higher that nothing gets done about it at all.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.