My unease with snap, and in particular apt wrappers that install snaps, made manifest.
https://linuxsecurity.com/news/hackscracks/crypto-stealing-malware-hits-snap-packages
My unease with snap, and in particular apt wrappers that install snaps, made manifest.
https://linuxsecurity.com/news/hackscracks/crypto-stealing-malware-hits-snap-packages
tl;dr: There’s a relentless campaign by scammers to publish malware in the Canonical Snap Store. Some gets caught by automated filters, but plenty slips through. Recently, these miscreants have changed tactics - they’re now registering expired domains belonging to legitimate snap publishers, taking over their accounts, and pushing malicious updates to previously trustworthy applications. This is a significant escalation. Context Snaps are compressed, cryptographically signed, revertable software packages for Linux desktops, servers, and embedded devices.
tl;dr: There’s a relentless campaign by scammers to publish malware in the Canonical Snap Store. Some gets caught by automated filters, but plenty slips through. Recently, these miscreants have changed tactics - they’re now registering expired domains belonging to legitimate snap publishers, taking over their accounts, and pushing malicious updates to previously trustworthy applications. This is a significant escalation. Context Snaps are compressed, cryptographically signed, revertable software packages for Linux desktops, servers, and embedded devices.
𝗦𝗻𝗮𝗽𝗖𝗿𝗮𝗳𝘁:
https://thewhale.cc/posts/snapcraft
A universal app store for Linux. Deliver and update your app on any Linux distribution for desktop, cloud, and Internet of Things.
Oh dear. How does this get through any kind of validation!?
#linux #snapcraft
The Bad People are repeatedly, successfully uploading crypto malware to the #Linux #snapcraft Snap Store today! Way more than usual. Most masquerade as basic apps, then upload their malware as an update.
Runner up in "problematic downstream/distros packaging behavior" is #Canonical insisting on packaging old buggy versions in #Ubuntu using their endemic #Snap format. Ex.: https://snapcraft.io/gnome-calendar
It'd be really nice if they'd stop doing that, this is absolutely detrimental to the app's developers.
#SnapCraft creates confusion, until users eventually go out of their way to surgically remove it from their desktop OS in the same way Raiden rips out spines to acquire electrolytes.