Salta al contenuto principale



Threads adds 'ghost posts' that disappear after 24 hours


#meta


I got infected like an idiot


I downloaded a cracked install from tpb (haxnode). It was a loader exe that loaded the original exe and supposedly removed the drm in RAM. It required admin permissions, I didn't trust it, but i ran in a vm and nothing happened.

Then i told myself "i have microsoft defender and windows firewall control, they will warn me" and I ran it in my main laptop, and still nothing happened. Like, literally nothing happened. The original program would not start. It would simply exit. Nothing. The other 6 almost identical torrents from the same uploader but with a different program version had a similar result. I gave up.

Then i reboot, and firstly i notice a couple DOS prompts flashing on the screen, and windows firewall control asking me if "aspnet_compiler.exe" is allowed to access the internet or not.

Suspicious, i go to check that "aspnet_compiler.exe" and it's located in the .net system folder, i scan it with microsoft defender and it doesn't report as a virus. I do not pay attention to the fact that it doesn't have a valid Microsoft signature, and i tell myself "probably just a windows update" and i whitelist it on the firewall.

After a few hours I realize "wait a minute: it's impossible that an official windows exe isn't signed by microsoft!" I go back to scan it, not infected... or it looks like, defender says "ignored because in whitelist". What? The "loader" put c:* in the whitelist!

The "crack loader" wasn't a virus per se. It dropped an obfuscated batch in startup, which had a base64 encoded attachment of the actual malware, that was copied in the .net framework directory with unassuming names...

And this for a $60 perpetual license program that i should buy anyway because it's for work

in reply to Moonrise2473

a reminder that you do need an Antivirus in fact as a pirate. Oh People, stop listening to cybersec experts who spend their whole life using foss or buying legit software, they're in a different world from us pirates.

Also a reminder that it happens to the best of us anyway.

Questa voce è stata modificata (2 giorni fa)
in reply to zaknenou

Alternative if you want to be hardcore: air gap the system you run questionable software on.

If you're bored, you can even try to infect it with as much shit as possible.

Doesn't work as a test system though. Stuff lies dormant waiting for network access.

Questa voce è stata modificata (1 giorno fa)
in reply to Moonrise2473

No offense man. But sounds like typical windows user's mentality problem.


‘Tax the Rich!’: Packed Mamdani Rally Features Sanders, AOC, and Hochul Ahead of Election Day


“Ordinary people get one vote. Billionaires get the opportunity to spend as much as they want to elect the candidates they want,” [Senator Bernie] Sanders said, decrying the influence of super PACs that can accept unlimited political donations. “That is the context in which this election is taking place.”

[Alexandria] Ocasio-Cortez (D-N.Y.), meanwhile, cast the race as one that “mirrors what we are up against nationally, both an authoritarian criminal presidency, fueled by corruption and bigotry and an ascendant right-wing extremist movement,” as well as the “insufficient, eroded, bygone political establishment, this time in the form of Andrew Cuomo.”



Automattic accuses WP Engine of misleading practices


Automattic has filed new counterclaims against hosting company WP Engine in a long-running dispute over the use of the WordPress and WooCommerce brands.


Case file: automattic.com/wp-content/uplo…


in reply to BrikoX

Opt out is not real.

This will remove the widget entirely. If you think you might actually like the widget’s other features (calendar, weather, and news), you can “X” out a particular ad, and it won’t pop up again. But then you’ll get another ad.












Sora might have a 'pervert' problem on its hands


In the last week or so, 10 out of the 25 most popular cameos using my face are various fetishes, including one where I'm a centaur-woman pregnant with octoplets. It's not just me, either. I've seen this kind of content made with cameos of other women: female creators, another woman tech reporter, and a female employee of a prominent venture-capital firm.

**I don't get why anyone is surprised **




New Hampshire officials looking for feedback on new state climate action plan


It's important for residents to tell them how important it is to phase out fossil fuels as rapidly as possible.
in reply to silence7

INSTRUCTIONS FOR SUBMITTING COMMENTS:
NHDES will accept comments on its draft comprehensive measures until 4 pm, November 15, 2025. Only written
comments will be accepted. Comments may be sent by email (preferred) or postal mail. Please include your name,
organization, mailing address, email address and telephone number with your submittal.
The quality of stakeholder input matters more than quantity when it comes to public comments. NHDES prioritizes
specific, well-reasoned feedback supported by evidence over broad opinions. Please provide data and information,
understand the CCAP requirements, be innovative and constructive, include your background, clarify representation and
avoid form letters.
Please note the greenhouse gas reductions are preliminary estimates, which are still being reviewed and refined. We will
be revising the reductions as our modeling is finalized. We welcome comments on calculation approaches. There will be
an additional opportunity for comments on the final CCAP draft in spring 2026.
By email: cprg@des.nh.gov. Please include the following text in the subject line: “Draft CCAP Measures - Public Notice -
for New Hampshire’s Comprehensive Climate Action Plan.”
in reply to silence7

Whatever they're doing, it's not enough. The only feedback I can give any state is "try harder"
Questa voce è stata modificata (3 giorni fa)




Novità Netflix a novembre 2025: calendario completo di film e serie TV


Tra grandi ritorni, miniserie inedite e cinema d’autore, il catalogo delle novità di Netflix per Novembre 2025 si aggiorna con numerosi titoli. A novembre spiccano la parte 1 di Stranger Things 5, la miniserie storica Death by Lightning, la serie spagnola Il cuculo di cristallo dal romanzo di Javier Castillo, e il nuovo Frankenstein di Guillermo del Toro. In agenda anche la rom-com Buon Natal-ex! e il dramma Train Dreams.

SCOPRILI TUTTI QUI: Novità Netflix a novembre 2025: calendario completo di film e serie TV



Docker Alternative: Podman on Linux


Docker Alternative: Podman on Linux #linux #podman
linuxblog.io/docker-alternativ…


Monday, October 27, 2025


Russian drone attack targets residential buildings in Kyiv, killing civilians -- Russia’s war on civilians -- Ukraine retakes 2 villages in Donetsk Oblast near Dobropillia -- HUR says, as sabotage fires spread across Russia -- More than Tomahawks: what Uk

Share

The Kyiv Independent [unofficial]


Millions read the Kyiv Independent, but only one in 1,000 supports us financially

BECOME A MEMBER

Russia’s war against Ukraine


Psychologists aid residents in a yard of an apartment building hit by a Russian drone strike on Oct. 26, 2025 in Kyiv. A nighttime Russian drone attack on Kyiv damaged apartment buildings, injured residents, including children, and killed three people. (Vitalii Nosach/Global Images Ukraine via Getty Images)

Russian drone attack targets residential buildings in Kyiv, killing civilians. Russia launched a drone attack on Kyiv overnight Oct. 26, killing three people and injuring at least 32, including seven children, in strikes on residential buildings.

Ukraine retakes 2 villages in Donetsk Oblast near Dobropillia. Ukrainian forces liberated two villages in eastern Donetsk Oblast about 30 kilometers (19 miles) north of embattled Pokrovsk, the General Staff of Ukraine’s Armed Forces said on Oct. 26.

Ukrainian drones target Moscow in overnight attack, mayor says. Moscow’s Domodedovo and Zhukovsky airports temporarily suspended operations in response to the drone threat.

Your contribution helps keep the Kyiv Independent going. Become a member today.

‘More to come,’ HUR says, as sabotage fires spread across Russia. Russia faces an increase in the arson and “spontaneous combustion” of electrical panels, railway relay cabinets, and other infrastructure helping Moscow wage its war against Ukraine over the past week, a source at Ukraine’s military intelligence told the Kyiv Independent.

Russia says it tested nuclear-powered Burevestnik cruise missile. “It’s a unique product that no one else in the world possesses,” Russian President Vladimir Putin claimed.

Ukraine destroys Russian Buk air defense system worth $45 million, military says. Ukraine’s “Black Forest” brigade detected and struck a Russian Buk-M3 anti-aircraft missile system at an unspecified location.

YOU MAY ALSO BE INTERESTED IN…

War Notes

Get the latest news from the front lines in your inbox every Friday

SUBSCRIBE

Read our exclusives


Ukraine war latest: 3 killed, 32 injured in Kyiv amid Russian drone attack on residential buildings

President Volodymyr Zelensky said on Oct. 26 that Russia had launched more than 50 missiles, nearly 1,200 strike drones, and more than 1,360 guided bombs against Ukraine this week.

Photo: State Emergency Service/Telegram

Learn more

More than Tomahawks: what Ukraine’s soldiers say they actually need

Though Ukraine has been hoping the U.S. will finally greenlight the supply of long-range Tomahawk missiles, those on the ground say the lack of more basic needs is a more pressing issue.

Photo: Roman Pilipey/AFP via Getty Images

Learn more

YOU MAY ALSO BE INTERESTED IN…

One story from Ukraine

Monday to Friday, get an email with our most important story of the day

SUBSCRIBE

Russia’s war on civilians | Ukraine This Week

Human cost of war


At least 9 killed, 45 injured in Russian strikes across Ukraine over the past day. At least nine civilians were killed and 44 others injured in Russian attacks across Ukraine over the past day, regional authorities reported on Oct. 26.

Millions read the Kyiv Independent, but only one in 1,000 supports us financially. One membership might not seem like much, but to us, it makes a real difference. If you value our reporting, consider becoming a member — your support makes us stronger.

BECOME A MEMBER

MAKE A DONATION

International response


Lithuania closes border with Belarus indefinitely after balloons violate airspace for 3rd night in row. “Contraband” balloons launched from Belarus have disrupted air traffic four times in the last week. Lithuania has closed border crossings with Belarus for “an indefinite period” in response.

Ukraine Action Summit meets in Washington, calls for return of abducted children, security guarantees. “We bring people together to learn… to educate themselves and to use their voices to speak to their elected officials to support Ukraine,” Marianna Tretiak, Chair of the American Coalition for Ukraine (ACU) Board, told the Kyiv Independent.

YOU MAY ALSO BE INTERESTED IN…

WTF is wrong with Russia?

A weekly newsletter about Russian politics, history, and culture

SUBSCRIBE

This newsletter is open for sponsorship. Boost your brand’s visibility by reaching thousands of engaged subscribers. Click here for more details.

Today’s Ukraine Daily was brought to you by Jared Goyette, Asami Terajima, Tymur Zadorozhnyy, Volodymyr Ivanyshyn, and Abbey Fenbert.

If you’re enjoying this newsletter, consider joining our membership program. Start supporting independent journalism today.

Share

#russia #video #belarus #lithuania #blog #nuclear #infrastructure #children #vlog #genocide #railway #military #ukrainian #Ukraine #drones #homes #Putin #BelarusBorder #warcrimes #moscow #Apartments #украина #balloons #Kyiv #путин #русский #PutinWarCrimes #CrimesAgainstHumanity #RussianWarCrimes #missiles #terrorists #houses #blackforest #BasicNeeds #Киев #геноцид #Airports #brigade #russianterrorists #arson #russianterrorism #residents #Pokrovsk #RussianAggression #ukrainianchildren #kidnapped #abducted #KyivIndependent #Hur #domodedovo #internationallawviolations #ACU #TomahawkMissiles #Zhukovsky #ukrainiansoldiers #villages #killingcivilians #psychologists #securityguarantees #russianstrikes #russianattacks #ukrainiandrones #dronethreats #CiviliansTargeted #russiandronestrikes #nuclearpowered #dobropillia #abductedChildren #civiliansAttacked #civiliansTortured #DonetskOblast #Военныепреступления #moscowairports #antiaircraft #residentialAreas #apartmentBuildings #nuclearTerrorism #Гражданские #нападавшиенапытку #Преступленияпротивчеловечности #Русскиесмерти #убитые #цивилийцы #airspaceViolations #bukm3 #Tomahawks #burevestnik #borderClosed #BukAirDefense #BurevestnikCruiseMissile #civiliansShot #electricalPanels #railwayRelayCabinets #RussiaSWarOnCivilians #RussianKidnappers #sabotageFires #spontaneousCombustion #suspendedOperations #targetMoscow #targetingResidentialBuildings #UkraineActionSummit #violateAirspace #whatTheyNeed


6 novembre 2025 18:30:00 CET - GMT+1 - 568 Public House, 00145, Rome, Italy
Nov 6
🍹 Log Out @ Roma
Gio 18:30 - 21:30
Tech Workers Coalition Italia

Giovedì 6 novembre torniamo con il Logout di TWC Roma, il ritrovo per tech workers che vogliono incontrarsi dopo lavoro: un'occasione per socializzare, conoscersi, parlare del nostro lavoro e come organizzarci nei prossimi mesi!

Ci vediamo giovedì 6 novembre, alle 18.30, da 568 Public House a Garbatella!

Unisciti al Gruppo telegram!

reshared this




La tua fallacia sul ciclismo è… “Dove vivo è troppo umido/secco/ventoso/caldo/freddo per andare in bicicletta”


[h1][url=https://www.cyclingfallacies.org/en/the-weather-isnt-right.html]La risposta[/url][/h1] Se fa troppo freddo, o è troppo umido, o è troppo caldo per andare in bicicletta, allora è generalmente troppo freddo, o è troppo umido, o è troppo caldo per

La risposta


Se fa troppo freddo, o è troppo umido, o è troppo caldo per andare in bicicletta, allora è generalmente troppo freddo, o è troppo umido, o è troppo caldo per uscire. Quando le strade sono ben progettate, non si è più in balia delle intemperie quando si va in bicicletta di quanto lo si sia quando si cammina.

I Paesi Bassi e la Danimarca sono abitualmente caratterizzati da inverni molto freddi, ma una buona gestione delle condizioni, inclusa la rimozione della neve dalle principali piste ciclabili, garantisce che la bicicletta rimanga un mezzo di trasporto pratico per la maggior parte delle persone. Le persone continuano a camminare quando piove, fa freddo o fa caldo, e continuano anche ad andare in bicicletta. Le ricerche suggeriscono che nelle città con infrastrutture ciclabili di alta qualità, le persone continuano ad andare in bicicletta regolarmente anche in caso di maltempo. È solo nelle località con reti ciclabili scadenti o assenti che i livelli di ciclabilità diminuiscono in caso di maltempo.

Anche se in alcuni luoghi le condizioni sono talmente estreme che andare in bicicletta risulta davvero difficile, per la maggior parte dei luoghi questo non è vero e non giustifica in alcun modo la mancanza di un ambiente sicuro e piacevole per andare in bicicletta.

reshared this




[AVAILABLE] Freelance Developer – Python | Django | Node.js | Next.js | TypeScript | Automation | ML ‼️🚨‼️🚨


Hi! I’m a freelance developer experienced in Python (Django, FastAPI), Node.js, Next.js, TypeScript, automation, and machine learning.
I’m currently seeking small freelance projects to build real-world experience.
I can work for free or at low cost depending on the scope.
If you need help with web apps, automation, or AI-based projects, PM me here on Reddit — happy to collaborate and grow together!
Check my profile: linkedin.com/in/orbin-sunny
github.com/orbin123
— Orbin>



The People’s Answer to ICE: Crowdsourcing Community Defense


reshared this



The People’s Answer to ICE: Crowdsourcing Community Defense


reshared this



The People’s Answer to ICE: Crowdsourcing Community Defense


reshared this



The People’s Answer to ICE: Crowdsourcing Community Defense


reshared this




Le Comunità Energetiche Rinnovabili, cosa sono.


Stanno nascendo sul territorio le Comunità Energetiche Rinnovabili (CER).
Stanno nascendo sul territorio le Comunità Energetiche Rinnovabili (CER). Come spiegato sul sito del GSE (Gruppo Servizi Energetici), una CER è "un insieme di cittadini, piccole e medie imprese, enti territoriali e autorità locali, incluse le amministrazioni comunali, le cooperative, gli enti di ricerca, gli enti religiosi, quelli del terzo settore e di protezione ambientale, che condividono l’energia elettrica rinnovabile prodotta da impianti nella disponibilità di uno o più soggetti associatisi alla comunità. In una CER l’energia elettrica rinnovabile può esser condivisa tra i diversi soggetti produttori e consumatori, localizzati all’interno di un medesimo perimetro geografico, grazie all’impiego della rete nazionale di distribuzione di energia elettrica, che rende possibile la condivisione virtuale di tale energia."
Per saperne di più, il sito del GSE dedica una sezione apposita.
gse.it/servizi-per-te/autocons…

Majden 🍉🎨🕊👠 reshared this.



Lawmakers float a nationwide basic income experiment that would cover the cost of a 2-bedroom apartment


The idea was proposed by two Democrats, so you know it has zero chance in this administration.

in reply to ickplant

We have tons of halloween stuff in Italy even if it's not in our tradition.
Halloween here in Italy pretty much exists just to make big corpos happy



Sufjan Stevens - Carrie & Lowell (2015)


“I don’t know where to begin”. Difficile immaginare una confessione più disarmata, per uno che di mestiere fa il cantastorie. Scoprirsi così sopraffatti da aver perso le parole. Da aver paura persino di affrontare il silenzio... Leggi e ascolta...


Sufjan Stevens - Carrie & Lowell (2015)


immagine

“I don’t know where to begin”. Difficile immaginare una confessione più disarmata, per uno che di mestiere fa il cantastorie. Scoprirsi così sopraffatti da aver perso le parole. Da aver paura persino di affrontare il silenzio. Difficile immaginarlo soprattutto per uno come Sufjan l’eclettico, quello del giro dell’America in cinquanta album e delle lettere aperte a Miley Cyrus su Tumblr. Ma in “Carrie & Lowell” le cose sono diverse: “Questo non è il mio progetto artistico. Questa è la mia vita”. E il gioco dei trasformismi lascia il posto alla carne e al sangue dell’esperienza... artesuono.blogspot.com/2015/04…


Ascolta il disco: album.link/s/64xtjfsPHNHch0CZ7…


HomeIdentità DigitaleSono su: Mastodon.uno - Pixelfed - Feddit




Look Out for These 8 Big Ag Greenwashing Terms at COP30


[quote]Food and farming companies will claim agriculture is the solution to the climate crisis at the Brazil summit — even though food drives a third of global warming.[/quote]
Food and farming companies will claim agriculture is the solution to the climate crisis at the Brazil summit — even though food drives a third of global warming.

in reply to ickplant

I wouldn't be comfortable leaving my dog outside at night in a place where bears roam


Wild animals officially recognised as solutions to climate change


The decision follows mounting evidence that wild animals are not just passengers in climate discussions but are powerful actors. From elephants dispersing the seeds of carbon-dense trees, to whales enhancing oceanic carbon pumps, wild animals shape the health and carbon-storage capacity of ecosystems across land and sea.
Questa voce è stata modificata (3 giorni fa)



L'ultimo libro di Giancarlo Pontiggia


Una riflessione di Giancarlo Pontiggia intorno al suo ultimo libro.



Portland, OR.


I cannot believe the incredible sarcasm put forth by city services. I hope I managed to capture it in this photograph.

I mean, if there was barbed wire on top of an exclusionary plywood wall that said "compassion" in some movie somewhere, it would be rightly criticized as being heavy-handed.

Thanks for seeing my work.





Scoperto il regista della rigenerazione degli arti negli axolotl - Biotech -




La storia frammentata e il destino ignoto del tesoro che avrebbe restaurato la monarchia inglese - Il blog di Jacopo Ranieri




ICE Will Use AI to Surveil Social Media




Middle gray


In photography, painting, and other visual arts, middle gray or middle grey is a tone that is perceptually about halfway between black and white on a lightness scale; in photography and printing, it is typically defined as [strong]18% reflectance in visib
In photography, painting, and other visual arts, middle gray or middle grey is a tone that is perceptually about halfway between black and white on a lightness scale; in photography and printing, it is typically defined as 18% reflectance in visible light.


I have just switched to Android - what are some good F-droid apps to install?


First off, I have already installed and am happy with (I don't need any suggestions for these):
- Fennec (browser)
- Heliboard (keyboard, it's awesome!)
- Aves (image gallery)
- AntennaPod (podcasts)
- DAVx^5^ + Etar (calendar)
- Fossify Calendar looks nice, but is less functional in my opinion (you can't see the full name of events in month view!)
- Joplin (notes)
- CalcYou (calculator)
- Breezy Weather
- CoMaps
- Thunderbird (email)
- Material Files (file manager)
- Chrono (alarms, timers, etc.)
- ConnectYou (contacts)
- Fossify Messages (SMS)
- also considering Quik SMS, does it have any advantages over Fossify?
- Moshidon (Mastodon)
- RSS feed reader (Feeder + CapyReader, one of the two probably, both are great)
- Image Toolbox
- My self-hosted stuff (Nextcloud and Immich)
- KeePassDX (password manager)
- Ente Auth (2FA)

I currently need:
- music player (Metro and Vanilla Music are both unmaintained, so those are out. I've also found Auxio, CuteMusic, Lotus, and Phocid as options. Are there any other good ones? I want local playback, not stuff using YT Music)
- Lemmy client (Jerboa crashes when trying to log in for some reason, I've heard Thunder might be good?)
- are there any other apps I should look at?

Another thing, is there a guide to what all the settings in Heliboard do? It's kind of overwhelming. One thing I have changed is the "bottom padding" to make the space bar a bit up, since I accidentally press "c" and "v" way too often when trying to hit space. Also, being able to enable the number row is pretty cool!

Questa voce è stata modificata (3 giorni fa)
in reply to sbird

Offline Translator is cool, but the description didnt do it justice. Its a combined OCR + translator app. So you can just take a pic of some random text or sign somewhere and it will translate and overlay the text on the image.
in reply to unexposedhazard

You are right, it is quite amazing. And very fast too, on my Pixel 4a (2020)


The Yangtze River Is Becoming the World’s Largest Electrified Trade Corridor


Fun looking at China and seeing plans for the future, while here, it's nothing but grift for the foreseeable future.

Port electrification follows a predictable sequence. The first stage replaces diesel cranes, trucks, and yard equipment with electric systems. The second extends to tugs and harbor craft. The third, which is now underway in China, reaches inland and short-sea vessels. The fourth will see ports functioning as full energy hubs, feeding deep-sea hybrids and stabilizing regional grids. Every stage builds on the one before it. Once the ground vehicles and cranes switch to electric drive, high-capacity chargers and energy management systems are already in place. Those same assets can serve harbor craft and ships. Electrification propagates by infrastructure reuse.

The Yangtze River has become a living demonstration of this process. It connects the interior manufacturing centers of Chongqing, Wuhan, and Yichang with the export hubs of Shanghai, Nanjing, and Ningbo. Along its length, the physical river has been matched by a set of electrical arteries. Two of them, the Changji–Guquan and Hami–Chongqing UHVDC transmission lines, deliver more than 30 TWh of renewable power each year from the deserts and plateaus of the west to the dense industrial east. Together they provide up to 8 GW of clean capacity directly into the Yangtze corridor. These ultra-high-voltage direct current lines are the spine of a new energy geography, making clean electrons available where cargo and industry already cluster. Without that grid backbone, even the most efficient electric ship would be an isolated experiment.


There's tremendous irony regarding one point ...

This is against a backdrop of radical change in shipping volumes. 40% of all tonnage is of fossil fuels and all are in structural decline. Another 15% is raw iron ore, also in structure decline. Population growth is slowing and the global population is expected to peak between 2050 and 2070. While container shipping will continue to grow, it won’t be growing nearly as fast as bulks decline.


Entrevista | Claudia Espinoza avalia o futuro político da Bolívia




ICE Will Use AI to Surveil Social Media


cross-posted from: lemmy.bestiver.se/post/700961

Comments


Best way to use Onedrive?


Before anyone says it, yes, I know it's shit, and that Microsoft are awful, but my wife needs Office, so I get a couple of accounts with 1TB of storage for free, so I may as well use it.

I've got my PC, my laptop, and a Synology DS216 (I think) NAS that I want to keep synced and backed up. I was using Onedrive on the PC to sync to their online storage, and using Syncthing to keep the laptop and Synology updated, but they just mirrored the PC. The PC was the only one that could write to the folder.

I want to keep the PC and laptop synced in both directions, and use the Synology and Onedrive as extra copies. I know it's not a proper backup, but it's better than nothing for the moment.

Would I be better off installing Onedrive, or Abraunegg's version, on the three systems and letting it sync, or putting Onedrive on the Synology and using Syncthing to keep the folders synced?

I'll have Onedrive on the Synology either way, and I'll be using Syncthing on all three to keep my music synced with my media server, so I'm mostly wondering whether people think it's better to let just the Synology sync to Onedrive, or to have a client on each device.

The three devices are pretty much always used in the same house, but very occasionally the laptop is taken out, almost always to somewhere with an internet connection.

Thanks 😀

in reply to Tippon

GNOME has a built in OneDrive integration, and it works well from my experience, one of the reasons I decided to stay on this DE

It acts a an additional directory tho, I'm unsure about your use-case



la sorpresa malwarica della domenica (l’attacco alla supply chain di OpenVSX mi fa passare brutti minuti)


Dopo i vari complotti ai miei danni… e prima gli scherzi degli spiriti, e poi i malware autunnali che colpiscono il mio corpo, e pure tutte le cose pericolosamente problematiche per essere anche solo scritte… Oggi pomeriggio mi è arrivata un’altra sorpresa: i fottuti virus sul PC. (E no, non è perché sto continuando ad […]

octospacc.altervista.org/2025/…


la sorpresa malwarica della domenica (l’attacco alla supply chain di OpenVSX mi fa passare brutti minuti)


Dopo i vari complotti ai miei danni… e prima gli scherzi degli spiriti, e poi i malware autunnali che colpiscono il mio corpo, e pure tutte le cose pericolosamente problematiche per essere anche solo scritteOggi pomeriggio mi è arrivata un’altra sorpresa: i fottuti virus sul PC. (E no, non è perché sto continuando ad usare Windows 10 una decina di giorni dopo la data di fine vita… non c’è nessuna falla nel sistema operativo di mezzo, bensì, anche stavolta, solo i potery forty.) 😰
💖💣, [26/10/2025 13:19]https://www.truesec.com/hub/blog/glassworm-self-propagating-vscode-extensionpotrei avere malware sul PC.💖💣, [26/10/2025 13:20]💖💣, [26/10/2025 13:20]💖💣, [26/10/2025 13:21]ma come cazzo si fa.💖💣, [26/10/2025 13:24]ora devo fare una scansione completa sperando di non trovare niente.
Ho semplicemente aperto VSCodium per fare la mia programmazione, perché sennò il fine settimana non sono contenta, lo sappiamo già… ed è arrivato un popup di Windows Defender, che si lamentava di un file JavaScript nella cartella di un’estensione installata dell’IDE. Purtroppo, cercandolo online, scopro che il merdone ha probabilmente ragione: il file è probabilmente infetto (non lo so con certezza, perché non volevo sbloccarlo col rischio che venisse eseguito, quindi l’ho fatto sparire)… perché, a quanto sembra, c’è stato di recente un attacco alla filiera (o “supply chain“, come piace dirlo agli altri) che ha colpito alcune estensioni VSCode… e zio cane. 😐

I link interessanti sono su memos.octt.eu.org/m/GdeyW5UqDV…, e stavolta sono forse interessanti davvero, perché il malware, “GlassWorm“, è una cosa assurda, a livello tecnico… Usa la blockchain di Solana per salvare i riferimenti allo stage 2, probabilmente per essere indistruttibile, perché se qualcuno gli leva di mezzo il server di comando e controllo questi possono sempre aggiornare il payload sulla blockchain e avere tutto ancora funzionante, una roba da pazzi… e poi, il codice malevolo nascosto nei file JavaScript è codificato con caratteri Unicode che appaiono vuoti, ma ovviamente vengono decodificati in quello che serve, e bleah. Ma non è questo il punto… 🤥

In pratica, quello che è successo — e non capisco perché lo scopro solo ora, e non mi sia invece arrivata indirettamente la notizia pochi giorni fa — è che questo malware prende di mira le estensioni per VSCode — principalmente quelle ospitate su OpenVSX, ma si sa già di almeno una infetta anche sullo store di Microsoft — per replicarsi e diffondersi sui PC degli sviluppatori di software, e da lì fare cose brutte… Innanzitutto rubare i dati di varie estensioni browser di criptovalute (e vabbè che se tieni le criptovalute sul PC anziché sul telefono stai proprio chiedendo che ti vengano rubate), perché evidentemente questi stronzi non hanno fantasia… poi credenziali Git, NPM, OpenVSX, questa roba qui, appunto per spargere codice malevolo… e, si dice, installare varie schifezze persistenti. 😭

Non so se sia più ironico il fatto che non ho praticamente mai beccato malware sui PC in anni e anni di pirateria e cose particolari, eppure mi deve succedere oggi in un modo che non potevo ragionevolmente prevenire — anche perché io non installo estensioni troppo ad minchiam, nel possibile faccio attenzione, ma a volte tocca installare il pacchetto sfigato gestito da qualcuno a caso non malevolo, ma che suo malgrado si è fatto bucare — per il solo peccato di scrivere codice ed usare VSCodium per farlo… Oppure, se la cosa che veramente mi deve far incazzare è che le estensioni bucate sono per ora ancora una quindicina, eppure proprio una (1) è capitato che l’avessi, quindi che combinazione… Ma è tutto così fottutamente assurdo. 💥

Per fortuna, (anche se non so quanto devo davvero fidarmi di un simile risultato, e mi chiedo se forse non dovrei prendere provvedimenti più forti; ma se devo cambiare le password impazzisco, e idem se devo reinstallare il sistema, quindi spero di no…) da diverse scansioni complete, una con Defender ed una con Kaspersky, esclusi i file dell’estensione infetta che poi ho giustamente anche disinstallato da VSCodium, il PC risulta pulito; e, anche controllando a manina i servizi di Windows, le operazioni programmate all’avvio, e le chiavi di registro riportate negli articoli sopra, non ho trovato nulla di strano, così come non vedo richieste agli indirizzi IP noti di questo merdone attraverso WireShark. 🙄

Quindi… è possibile che Defender abbia bloccato il codice malevolo in un momento in cui si, l’IDE ha letto il file che lo conteneva, ma non effettivamente eseguito, perché questa estensione (sissel.shopify-liquid@4.0.1) magari non era una di quelle che gira a vuoto, e io in cosa stavo lavorando oggi (e ieri) non avevo niente che causasse l’effettivo caricamento dell’estensione? Mi verrebbe da chiedermi perché minchia la rilevazione sia avvenuta solo oggi, visto che l’estensione è bucata da apparentemente una bella settimana, e quindi dovevo avere in teoria già minimo da ieri la versione schifosa, visto che VSCode maledetto aggiorna in automatico le estensioni senza dire niente… ma evidentemente Microsoft ha il culo comodo nell’aggiornare le definizioni. 😤

Allora, in sostanza, spero vivamente che questo coglione marcio non sia riuscito ad installarmi sul computer RAT, HVNC, o proxy per i propri usi schifosi, altrimenti sono rogne… Se avete consigli, a parte l’idea di smettere di programmare software, vi ringrazio in anticipo; per ora ho disattivato l’aggiornamento automatico di tutte le estensioni, così, semmai qualcun’altra viene fottuta, io non lo sarò. Però, a parte gli scherzi, viviamo veramente in un mondo di merda se i malware non sono più “vinci la partita a carte se non vuoi che ti cancello il disco“, e invece sono “mi nascondo per fotterti”… e se per prenderli non serve fare nulla di incauto, ma basta appena esistere ed usare software scritto da altri!!! 😩

#GlassWorm #malware #OpenVSX #virus #VSCode