# Sneaky devils: beware links to malware on GitHub

**URL:** <https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651>\
**Category:** Offtopic\
**Tags:** github, malware\
**Created:** [August 27, 2024, 1:13am UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651 "2024-08-27T01:13:54Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [August 27, 2024, 1:13am UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/1 "2024-08-27T01:13:55Z")

</div>

Posted an issue. Someone apparently on Github (it looked like a totally legitimate page `https://github.com/NeonRST`) suggested I download and install something from a link they provided. I said no thank you, I don’t install things I don’t know what they are, and five minutes later that page and the post were gone.

Beware!

Edit: It seems that many of you were seduced by the link above to click on it. Of course, it was in the meantime deleted and hence is dead. I fixed that.

---

<div class="post-metadata">

**Author:** ![asinghvi17](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/asinghvi17/32/8272_2.png) [@asinghvi17](https://discourse.julialang.org/u/asinghvi17)\
**Post date:** [August 27, 2024, 4:53am UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/2 "2024-08-27T04:53:19Z")

</div>

I’ve seen this as well on a couple of repos, reported it to Github and deleted it. This seems to be pretty prevalent across communities, I’ve seen quite a few maintainers mention this kind of thing.

---

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [August 28, 2024, 12:41pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/3 "2024-08-28T12:41:22Z")

</div>

Where does one report this?

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [August 28, 2024, 1:00pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/4 "2024-08-28T13:00:33Z")

</div>

You can report it to Github while the code is there, but the best they can do is remove it, so it if is gone then that’s it.

In theory your local police may have a cybercrime unit, but they usually focus on larger crimes. Unless you were actually scammed, lost money, or had a security breach with access to sensitive data, they may not prioritize it as these scam attempts are very common and the perpetrators are difficult to track.

---

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [August 28, 2024, 1:10pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/5 "2024-08-28T13:10:42Z")

</div>

Right. But at the least, Github could try to make it more difficult to create fake personas/profiles?

---

<div class="post-metadata">

**Author:** ![lrnv](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/lrnv/32/19373_2.png) [@lrnv](https://discourse.julialang.org/u/lrnv)\
**Post date:** [August 28, 2024, 1:34pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/6 "2024-08-28T13:34:50Z")

</div>

1. Any fake person is not necessarily malicious nor criminal and 2. the right to alias yourself seems necessary for freedom of speech

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [August 28, 2024, 1:48pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/7 "2024-08-28T13:48:28Z")

</div>

> [@Tamas\_Papp](#):
>
> but the best they can do is remove it, so it if is gone then that’s it.

First reporting then deleting is probably better, as github can also delete entirely the account. If you only delete without reporting they probably won’t do anything about it.

---

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [August 28, 2024, 2:09pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/8 "2024-08-28T14:09:22Z")

</div>

I think it would be perfectly adequate if Github mandated a delay of a few days for the creation and deletion of a profile. If a profile can be deleted right away, there is no time for someone to report that profile for malfeasance. Similarly, if profile creation does not cost any time, a window is opened for someone to create one on the fly to fit a purpose.

---

<div class="post-metadata">

**Author:** ![mbauman](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/mbauman/32/31082_2.png) [@mbauman](https://discourse.julialang.org/u/mbauman)\
**Post date:** [August 28, 2024, 2:22pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/9 "2024-08-28T14:22:18Z")

</div>

Welcome to the internet, where [nobody is a real person](https://en.wikipedia.org/wiki/Dead_Internet_theory). 🙂 Seriously, though, combating bots and/or bad behavior is _hard_. I expect that it was GitHub who deleted that account due to the bad behavior. And it seems they did it right quick. I _suppose_ the bad actor could’ve done it themselves to avoid detection, but I’d be very surprised — that limits the scope and duration of their attack.

Any large site needs to deal with this. I’m sure there are multiple engineers constantly working on it at GitHub.

---

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [August 28, 2024, 2:27pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/10 "2024-08-28T14:27:59Z")

</div>

> [@mbauman](#):
>
> I expect that it was GitHub who deleted that account due to the bad behavior.

That is precisely what is counterproductive here (if indeed it was Github itself; in this case I believe it was the malfeasant, since my comment indicated I was unto him/her). Not deleting that account, just disabling it or labeling it as malicious, would allow those that were harmed to demand redress.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [August 28, 2024, 4:21pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/11 "2024-08-28T16:21:40Z")

</div>

> [@PetrKryslUCSD](#):
>
> would allow those that were harmed to demand redress.

I am pretty sure they still have all the info in their logs if you want to go to court about this, but practically, even if you find the perpetrator, it is unlikely that you will be able to collect anything. So I would just ignore it and move on.

---

<div class="post-metadata">

**Author:** ![PetrKryslUCSD](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/petrkryslucsd/32/215825_2.png) [@PetrKryslUCSD](https://discourse.julialang.org/u/PetrKryslUCSD)\
**Post date:** [August 28, 2024, 4:25pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/12 "2024-08-28T16:25:05Z")

</div>

I am not saying that I want to pursue this action. I _am_ saying that introducing the profile creation/deletion delay at Github would potentially save a lot of headaches to a lot of people.

---

<div class="post-metadata">

**Author:** ![giordano](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/giordano/32/2166_2.png) [@giordano](https://discourse.julialang.org/u/giordano)\
**Post date:** [August 28, 2024, 5:58pm UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/13 "2024-08-28T17:58:42Z")

</div>

Github deletes the account if someone reports it.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [August 29, 2024, 10:55am UTC](https://discourse.julialang.org/t/sneaky-devils-beware-links-to-malware-on-github/118651/14 "2024-08-29T10:55:44Z")

</div>

> [@PetrKryslUCSD](#):
>
> introducing the profile creation/deletion delay at Github would potentially save a lot of headaches to a lot of people

Possibly, but at the same time it would also have costs for well-meaning users (delays) and Github (user frustration). The net benefit is unclear; malicious users could just create accounts in advance.

It seems that the basic problem is getting a message that was about downloading and running something unknown on your system. Github is not the only channel for that (it could happen on various forums, including this one).

It is best to just assume that every single online persona you are interacting with could be potentially malicious. Even acounts who have some history on a site, or someone you have interacted with in the past could be hiding someone with harmful intentions (accounts are occasionally hijacked). Just never run untrusted code.
