Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
Was that a page that made it look like one needs to do something as part of the browser/session human verification process? And it was an obfuscated command (an echo cmd iirc)? Sth like this <a href="https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attacks-macos-users" rel="nofollow">https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attac...
Great. I was able to do that in Gemini free web. Lots of copy/pasting, well, what an irony - but I was careful this time. Gave inputs in Gemini Web and then followed up. Didn't have a paid plan back then. I remember a dir name "luvmrtrump" or something. Haha.
I was lucky enough to stop at the password prompt (something felt off). Gemini had pretty much established that it was almost entirely certain nothing left my Mac as I didn't enter my password and I hadn't. It also found some evidence that had I entered my password those evidences would have been gone certainly from my mac and then I had the script beautified and de-obfuscated and read it myself and had a much needed sigh of relief. The script literally did nothing unless it had the password.
I started using nextdns after that but then the site I tricked on was a legit but very small e-com site from my country which was hacked/taken over, so not sure how nextdns can even be helpful here. Also the script was identified as malicious by only one antivirus that I had tried later, just to see. I had tried 8–9 of them. Later I uninstalled all of them and even stopped using NextDNS.
I wish browsers like Safari allowed specific options like disabling clipboard interaction instead of the "disable js" as the only possible option.
Later (and still) I feel a bit of shame that how could I fall for this as a somewhat proud cynic and as well versed in "browsing the Interwebs" as it normally gets :) That (as small as it was) experience gave a whole new meaning to malicious online attacks for me and a whole lot of empathy towards people who fall for such attacks. It was my first "experience". It might sound weird but the feeling of violation still lingers.
wg0 · · focus · HN ↗
Lately I found myself in middle of a hostile malware attack on my laptop which was my mistake. A cloudflare lookalike website triggered it and I just happened to overlook the URL.
In panic I headed to Claude and first request was denied. Not looking beyond scope.
Desperate - I fired opencode with DeepSeek v4 Flash (not even 4.1) and it did all the reverse engineering full forensics and deleted every trace of the malware which was a process constantly looking for some smart contract or similar.
So no, GLM 5.3 is fine. Thank you for the free advertisement.
crossroadsguy · · focus · HN ↗
Was that a page that made it look like one needs to do something as part of the browser/session human verification process? And it was an obfuscated command (an echo cmd iirc)? Sth like this <a href="https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attacks-macos-users" rel="nofollow">https://www.forcepoint.com/blog/x-labs/odyssey-stealer-attac...
Or was it something else?
wg0 · · focus · HN ↗
DeepSeek did full reverse engineering on this.
crossroadsguy · · focus · HN ↗
I was lucky enough to stop at the password prompt (something felt off). Gemini had pretty much established that it was almost entirely certain nothing left my Mac as I didn't enter my password and I hadn't. It also found some evidence that had I entered my password those evidences would have been gone certainly from my mac and then I had the script beautified and de-obfuscated and read it myself and had a much needed sigh of relief. The script literally did nothing unless it had the password.
I started using nextdns after that but then the site I tricked on was a legit but very small e-com site from my country which was hacked/taken over, so not sure how nextdns can even be helpful here. Also the script was identified as malicious by only one antivirus that I had tried later, just to see. I had tried 8–9 of them. Later I uninstalled all of them and even stopped using NextDNS.
I wish browsers like Safari allowed specific options like disabling clipboard interaction instead of the "disable js" as the only possible option.
Later (and still) I feel a bit of shame that how could I fall for this as a somewhat proud cynic and as well versed in "browsing the Interwebs" as it normally gets :) That (as small as it was) experience gave a whole new meaning to malicious online attacks for me and a whole lot of empathy towards people who fall for such attacks. It was my first "experience". It might sound weird but the feeling of violation still lingers.
(just wanted to share this)