This is the first time I'm posting anything here but I figured this may be the right audience.

I've never run into something like this and I don't quite know what to make of it. I'm the author and maintainer of libgpiod. The official git repository is the one at kernel.org[1]. There's also a github mirror[2] as well as a documentation page[3] at readthedocs that I maintain.

I noticed (purely by chance) that there's a new website at libgpiod.com that's been created recently. I have nothing to do with it. It's clearly AI-generated but it redirects to my github. It's a 2 month old domain, anonymized registrar, protected by Cloudflare and NeoProtect and a Swedish host behind that.

Clearly someone went to great lengths to stay anonymous. I'm afraid of falling victim to some new elaborate supply chain attack. What should I do about it (if anything)? Has anyone else experienced something similar?

[1] https://git.kernel.org/pub/scm/libs/libgpiod/libgpiod.git/
[2] https://github.com/brgl/libgpiod
[3] https://libgpiod.readthedocs.io/
Libgpiod - Modern C Library for Linux GPIO Hardware Control

Libgpiod is a modern C library for Linux GPIO control, enabling efficient hardware access for embedded and system developers. #Libgpiod

Libgpiod

@brgl

A quick check at VirusTotal doesn't reveal any detections, but it is clearly apparent that there's a direct link to the project, via the Meta Tags already presented to VT.

At the very least, head to VT and redo the scan for yourself, and start documenting everything you find from there and elsewhere.

@brgl

Another quick check at MXToolbox, shows the associated mail server is on a blacklist, tagged as "Rats Dyna".

"RATS-Dyna - Probable PC or home connection infected with a Trojan, Bot, or Emailer Program -- If you are listed in the Spamrats/RATS-Dyna blacklist and you operate your own mail server, you likely have no valid PTR-Record."

https://mxtoolbox.com

MX Lookup Tool - Check your DNS MX Records online - MxToolbox

@brgl

One last check - on a _very_ old tool - shows the not-so-anonymous registrar as, epik.com

@lumiworx @brgl oh, wow. Spade! Is that still a thing or have you simply kept it around?

@confuseacat @brgl

Well, I doubt it's considered a frontline tool these days, but it still works - well, most of it does - and I'm not one to toss something out because of its age or because its no longer maintained, while it offers a tidy group of some still-useful utilities in one package.

@lumiworx @confuseacat @brgl holy crap. I haven't seen that tool in ages. What's next? Are you going to whip out SATAN? :))))

@briankrebs @confuseacat @brgl

I have a pair of needle-nose pliers that are older than I am that I got from my father, so some things have sentimental value and a few less 'teeth', but have a comfortable and familiar grip.

But, no... no SATAN. lol