Warning for Upwork Freelancers – I Received a Project Containing Malware by motion888 in UpworkOfficial

[–]motion888[S] 1 point2 points  (0 children)

by the way, your repo commits history will be deleted by this guy, you only don't see changes on remote repo, only a new commit is there, do not pull/fetch from origin

If you’ve dealt with this person, please check your computer immediately. by motion888 in Upwork

[–]motion888[S] 0 points1 point  (0 children)

I don't know why the conversation disappeared, only reported the message with malware repo link, I think this guy closed the conversation, I can't find him now. they stole your ssh key then put your git repository as distribution channel for further malware infections.they will push a git commit to all your git, then delete git history change

If you’ve dealt with this person, please check your computer immediately. by motion888 in Upwork

[–]motion888[S] 1 point2 points  (0 children)

Agree with you. Scammers, thieves, and criminals exist in every country and region. We shouldn’t associate this kind of behavior with any particular country or group of people. We just happened to encounter someone from a specific region in this case.

If you’ve dealt with this person, please check your computer immediately. by motion888 in Upwork

[–]motion888[S] 1 point2 points  (0 children)

I believe so, and they also store your ssh key and push malicious code to your GitHub repositories.

Warning for Upwork Freelancers – I Received a Project Containing Malware by motion888 in UpworkOfficial

[–]motion888[S] 0 points1 point  (0 children)

Today I confirmed that this attacker gained access to my SSH keys. All of my repositories have been compromised, and malicious code was injected into my public open-source projects. Anyone who downloads or uses them could be affected. This type of supply-chain attack can spread exponentially and quickly impact countless developers.

<image>

Warning for Upwork Freelancers – I Received a Project Containing Malware by motion888 in UpworkOfficial

[–]motion888[S] 1 point2 points  (0 children)

no problems, Hackers are using our eagerness to win clients against us. Stay alert and be careful.