‹ BackHN Continuity

Thread

Why does mathmain need an encrypted loader?

138 points · 43 comments · abhisek

  1. j2kun · · focus · HN ↗
    Why in the world would that specific 3x3 matrix be a trigger for an attack? Are they trying to find someone doing some particular kind of numerical analysis?
    1. zarzavat · · focus · HN ↗
      Presumably it's so it can be used as a subdependency for setting up an attack in a popular, legitimate package, e.g. via a pull request. The code in the legitimate package would not arouse suspicion at all.
      1. krackers · · focus · HN ↗
        Now I'm curious what the target was. Are there any notable classes of programs/problems where you'd do an LU decomposition of this specific matrix?
        1. gruez · · focus · HN ↗
          >Are there any notable classes of programs/problems where you'd do an LU decomposition of this specific matrix?

          It doesn't have to be this specific matrix. If it's some service exposed to the internet, it can be user supplied, in which case it turns into a backdoor.

    2. tranceylc · · focus · HN ↗
      I would assume it’s actually so they can allow it to spread before it gets activated. Then do something that affects the entire chain of package dependencies
    3. coder-pm · · focus · HN ↗

      [dead]

      1. stymaar · · focus · HN ↗
        1. “The X is not Y, it's Z” 2. 3 months old account

        Bad bot.

        (I still wonder what these not operators have to gain in that process, but they sure want HN karma).

        1. smokel · · focus · HN ↗
          Interestingly, the presumed bot uses unicode apostrophes (’) instead of ', yet misspells "its".
          1. yorwba · · focus · HN ↗
            Tamping down on verbosity, removing em-dashes and adding misspellings are the obvious fixes to apply when your first attempts at spamming get flagged for being too on-the-nose: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;threads?id=coder-pm&amp;next=48716765">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;threads?id=coder-pm&amp;next=487167...
            1. tadfisher · · focus · HN ↗
              There are &quot;humanizer&quot; scripts that these people like to use. This one is not the typical style I see in my online moderator adventures, which is usually &quot;lowercase everything and remove all punctuation except periods&quot;, as if we are repelled by em-dash use and not the tortured prose.

              I like the removal of a random definite article, to simulate an ESL writer and garner sympathy for using LLMs as a &quot;tool to clean up posts&quot;. Heavens, they would never even think of using their Claude subscription to be a slop factory, that would cross a line.

        2. ajkjk · · focus · HN ↗
          gotta be careful. inevitably people will start emulating the LLM writing style since they&#x27;re so overexposed to it
        3. coder-pm · · focus · HN ↗
          Being new here doesn&#x27;t mean I&#x27;m a bot. I&#x27;m not native and maybe my style looks for you like a bot, I won&#x27;t try to argue with you. Just wanted to contribute
    4. ajkjk · · focus · HN ↗
      Perhaps they just need a way to sneakily activate it? Or perhaps they have a target application which they know uses that. This method suggests a supply chain attack where a valid contributor to a library &#x27;accidentally&#x27; includes this package and the hack carries out before anyone notices.

      My guess is that it&#x27;s crypto related but of course it could be anything.

    5. TimedToasts · · focus · HN ↗
      A status code for (industrial&#x2F;the-man) equipment? You could target specific environments by activating on obscure error codes that can be remotely triggered.

      Aka If someone from the outside can make your equipment emit X internally, they can target X in some way.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.