From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.io/gmane.text.pandoc/29748 Path: news.gmane.io!.POSTED.blaine.gmane.org!not-for-mail From: Jesse Newsgroups: gmane.text.pandoc Subject: Detected as trojan in chocolatey repo Date: Thu, 9 Dec 2021 13:25:13 -0800 (PST) Message-ID: <1ae0839c-ca1c-4845-8755-33235432ede2n@googlegroups.com> Reply-To: pandoc-discuss-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_Part_2402_6735797.1639085113919" Injection-Info: ciao.gmane.io; posting-host="blaine.gmane.org:116.202.254.214"; logging-data="1164"; mail-complaints-to="usenet@ciao.gmane.io" To: pandoc-discuss Original-X-From: pandoc-discuss+bncBD46HJ74TILRBO7IZGGQMGQE476XUOA-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org Thu Dec 09 22:25:17 2021 Return-path: Envelope-to: gtp-pandoc-discuss@m.gmane-mx.org Original-Received: from mail-ot1-f56.google.com ([209.85.210.56]) by ciao.gmane.io with esmtps (TLS1.3:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.92) (envelope-from ) id 1mvQuj-00005e-9x for gtp-pandoc-discuss@m.gmane-mx.org; Thu, 09 Dec 2021 22:25:17 +0100 Original-Received: by mail-ot1-f56.google.com with SMTP id v13-20020a056830140d00b0055c8421bd62sf2657587otp.15 for ; Thu, 09 Dec 2021 13:25:17 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=googlegroups.com; s=20210112; h=sender:date:from:to:message-id:subject:mime-version :x-original-sender:reply-to:precedence:mailing-list:list-id :list-post:list-help:list-archive:list-subscribe:list-unsubscribe; bh=QrDjHr7ZmlFOSjgZZG81utveIeGYyC581KBjuynjfZ4=; b=QK4TmryPa/+WDjbOuw10ZLlFSYdqegLUzPCZTXpUfr2SuGORTSODA7bw5vkjua/gSI IOCEcZURqD4GGQafSV9T/ZcCtVDgOYvnLiieOvjtonV42Zpt9kp06aWjIv+5jvaOdJJL UGTopvf+Z293D40C2FzeImQK6+L1ZhiCN2lLjTWuXdsBI7ZoGglW4tG3hoYzpX9JFYX+ EhK2pcbG6hWpbSJLHFIPHgXkic9dt6hbnAq5AKebx6c5MyHZpxzPXXLCBDmdx/Z6L1Ax FttrMHHeEkeTJV1HVM6A92e6uFxG9Ht77+6sUCQeJeXcBvTVuCq7PV60RePKLqmzBCIV RuCQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20210112; h=date:from:to:message-id:subject:mime-version:x-original-sender :reply-to:precedence:mailing-list:list-id:list-post:list-help :list-archive:list-subscribe:list-unsubscribe; bh=QrDjHr7ZmlFOSjgZZG81utveIeGYyC581KBjuynjfZ4=; b=mQ2g43tG2t96F/qmzcxHZk1gczzi2BTEv0IHSKSYXe0Y1Sbd3UAYborGj9sGO31C6a vMqBiHQ01p+xRLxJ4PFA0pUTnqEuZ4gVxf08srpAWeWd9X+5xgbAHomN8tYIDsVTsSYQ 8Dy9Y5Yt2+MgD4z1x0uQUs22OYEXU+xvaUHiEaBEvYSQnoLL+JHqTqLZR7Hz/WWbQL0l GB++TtqGl7rvXIzJBe/cnzXRBnzO1pHQo4/8ARgupVlUrtXlu2a2ea1YBsV9alhc7FwV mvf9VLIFGwQFfZu4eSRzHvvuKlB6AgEDSGEfL1993CqdzROSwI1trFmfXQqUMvLgKiay CH/g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20210112; h=sender:x-gm-message-state:date:from:to:message-id:subject :mime-version:x-original-sender:reply-to:precedence:mailing-list :list-id:x-spam-checked-in-group:list-post:list-help:list-archive :list-subscribe:list-unsubscribe; bh=QrDjHr7ZmlFOSjgZZG81utveIeGYyC581KBjuynjfZ4=; b=BkhgeOFFcUHziPpoCIoCqdpjPsgP3NKbw6r+ylvGNqHHH71DbS5EelzuXCcymhxaah kG/JpSaqgP62lf163CpI9Q3jUN0IrHsJ1OtbLz+juB4LqSCBh35G/YxkCpzhGA6SOrLM bjmgc/V0QCArP1+SzJExa+hVEXfO6mrCVYtOesgJ91O7/Tx18nWKOmHJw92/Mw1XG7gX DNRIv49kXtLHdkfCr/6/1nU0+Oj+tJGrXripLbzN3k5jEBALEqOE9vre6oPJjoRXyao5 cx3jFi9h6gKYAMtehDu8jWVPQs98VxmwFzrlOt2/+wUMgaJ1KAEDy1DdojI7g8thOZFo lCbQ== Original-Sender: pandoc-discuss-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org X-Gm-Message-State: AOAM532Up2sbLcQTvyaV+ptUWLeTITC3tp8eZ2Tdt8MQLuXDPBKAw4Os nBoz6QtI6hAlmYePjYVoaEI= X-Google-Smtp-Source: ABdhPJwn7/xjrdCs9FORN2bGy9mO/Ff0JhubKQVAI5DdGqERJ25LmZfXr1dyQPiHWxDGKffFHiC0pA== X-Received: by 2002:a54:4506:: with SMTP id l6mr8729663oil.32.1639085116279; Thu, 09 Dec 2021 13:25:16 -0800 (PST) X-BeenThere: pandoc-discuss-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org Original-Received: by 2002:a05:6830:3499:: with SMTP id c25ls1779820otu.4.gmail; Thu, 09 Dec 2021 13:25:14 -0800 (PST) X-Received: by 2002:a9d:1c86:: with SMTP id l6mr7674088ota.241.1639085114533; Thu, 09 Dec 2021 13:25:14 -0800 (PST) X-Original-Sender: jmrooster446-Re5JQEeQqe8AvxtiuMwx3w@public.gmane.org Precedence: list Mailing-list: list pandoc-discuss-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org; contact pandoc-discuss+owners-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org List-ID: X-Google-Group-Id: 1007024079513 List-Post: , List-Help: , List-Archive: , List-Unsubscribe: , Xref: news.gmane.io gmane.text.pandoc:29748 Archived-At: ------=_Part_2402_6735797.1639085113919 Content-Type: multipart/alternative; boundary="----=_Part_2403_930919679.1639085113919" ------=_Part_2403_930919679.1639085113919 Content-Type: text/plain; charset="UTF-8" Hello, are you the maintainer of your software on chocolatey? Do you have issues with false positives? Hope that's all this is. I don't even know why the repo installed this package; I didn't get a dependency error when I uninstalled it...maybe I removed the software it came with. The file was created on the 3rd, but didn't get picked up until a full drive idle scan this morning. So real-time missed it. Probably because I have chocolatey trusted. Everything is supposed to be scanned already, I thought. Then again, they offer integrated virus scanning as a paid feature; I hope that doesn't mean they don't scan pushed packages by default. Usually Kaspersky is pretty good about labeling PUA detections (will say *not-a-virus* right on the label) and it isn't heuristic either which is naturally a lot more likely to be false. So it tripped some signature. That doesn't mean it can't be a false positive though. Unfortunately I deleted the file before I thought to upload it to VirusTotal or send it in. I scanned the Windows zip and source code from Github to see if it caused a detection as well though and didn't detect anything. Also, *pandoc-citeproc.exe* is not in those archives anyway, perhaps those data are associated with the chocolatey package specifically? Just wanted to inform. I don't think anything bad happened to my PC. I hope it isn't indicative of someone somehow sneaking trojans into other legitimate chocolatey packages after they've been pushed to the repo. That seems like a stretch though. If you have any insight on this I'd appreciate it. I might just need to switch antivirus providers. Their firewall has been aggravating me for days as it is. Have a nice day. -- You received this message because you are subscribed to the Google Groups "pandoc-discuss" group. To unsubscribe from this group and stop receiving emails from it, send an email to pandoc-discuss+unsubscribe-/JYPxA39Uh5TLH3MbocFF+G/Ez6ZCGd0@public.gmane.org To view this discussion on the web visit https://groups.google.com/d/msgid/pandoc-discuss/1ae0839c-ca1c-4845-8755-33235432ede2n%40googlegroups.com. ------=_Part_2403_930919679.1639085113919 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable
Hello, are you the maintainer of your softwa= re on chocolatey? Do you have issues with false positives? Hope that's all = this is. I don't even know why the repo installed this package; I didn't ge= t a dependency error when I uninstalled it...maybe I removed the software i= t came with. The file was created on the 3rd, but didn't get picked up unti= l a full drive idle scan this morning. So real-time missed it. Probably bec= ause I have chocolatey trusted. Everything is supposed to be scanned alread= y, I thought. Then again, they offer integrated virus scanning as a paid fe= ature; I hope that doesn't mean they don't scan pushed packages by default.=

U= sually Kaspersky is pretty good about labeling PUA detections (will say not-a-virus right on the label) and it isn'= t heuristic either which is naturally a lot more likely to be false. So it = tripped some signature. That doesn't mean it can't be a false positive thou= gh. Unfortunately I deleted the file before I thought to upload it to Virus= Total or send it in. I scanned the Windows zip and source code from Github = to see if it caused a detection as well though and didn't detect anything. = Also, pandoc-citeproc.exe is not in those archives anyway, perhaps those data are associate= d with the chocolatey package specifically?

=
Just wanted to inform. I = don't think anything bad happened to my PC. I hope it isn't indicative of s= omeone somehow sneaking trojans into other legitimate chocolatey packages a= fter they've been pushed to the repo. That seems like a stretch though.

= If you have any insight on this I'd appreciate it. I might= just need to switch antivirus providers. Their firewall has been aggravati= ng me for days as it is. Have a nice day.

3D""

--
You received this message because you are subscribed to the Google Groups &= quot;pandoc-discuss" group.
To unsubscribe from this group and stop receiving emails from it, send an e= mail to pand= oc-discuss+unsubscribe-/JYPxA39Uh5TLH3MbocFFw@public.gmane.org.
To view this discussion on the web visit https://groups.google.com/d= /msgid/pandoc-discuss/1ae0839c-ca1c-4845-8755-33235432ede2n%40googlegroups.= com.
------=_Part_2403_930919679.1639085113919-- ------=_Part_2402_6735797.1639085113919--