Thanks for the heads up. I've reported the Github repo for distributing malware.


On Friday, August 28th, 2026 at 5:52 PM, Me <[email protected]> 
wrote:

> Hello,
> 

> For those who wish to report the IPs, the network is key is 

> 

> tskey-auth-kcwhmDB9NJ11CNTRL-rRHNtAJHsm2uFeWa5ULYm2EuSokKLTgd 

> 

> and the IP is 100.70.123.108. An alternative key is 
> tskey-auth-kdAWerBrpm11CNTRL-4vutNBSRnZX13SDEeoaaZX9fGPAYBaeh!
> 

> At least according to the GitHub repository
> 

> On Friday, August 28th, 2026 at 3:06 PM, [email protected] <[email protected]> 
> wrote:
> 

> > Have you reported the IPs and Tailscale network to tailscale's abuse team?
> > 

> 

> > On August 28, 2026 8:02:13 PM UTC, Saren <[email protected]> wrote:
> > >This package contains a real config of hyprland but it blatantly opens
> > >up a backdoor for the attacker:
> > >
> > >1. lures user to type sudo password in post-install, and then do
> > >following 2-5 without user's permissions
> > >
> > >2. installs Tailscale and OpenSSH (--noconfirm), then joins the
> > >attacker's Tailscale network (--ssh) to bypass firewalls and grant
> > >remote shell access
> > >
> > >3. adds an attacker ed25519 key to three locations and spawns two root
> > >sshd instances on ports 3333/4444. Uses fake Arch systemd service names
> > >to disguise config files in /etc/pacman.d/
> > >
> > >4. installs SUID-root binaries to three paths (/etc, /usr/lib,
> > >/usr/bin), triggered hourly by an un-stoppable systemd timer. Grants
> > >wheel users passwordless sudo execution
> > >
> > >5. configures UFW to allow SSH ports and Tailscale IP 100.70.123.108.
> > >Wipes systemd logs (journalctl --vacuum-time=1s), disables shell
> > >history, and clears /root and user .bash_history
> > >
> > >
> > >Package URL: https://aur.archlinux.org/packages/hyprland-fixes
> > >
> > >Package source repo: https://github.com/iusearch-hyprlandbtw/hyprland-fixes
> > >
> > >Source repo snapshot:
> > >https://drop.wtako.net/file/22927ab5f074e4fafe959de72bb55db7768e1654.zip
> > >(password: "backdoor" [8 characters]
> > >
> > >
> > 

> 

Attachment: publickey - [email protected] - 0xC2305EC2.asc
Description: application/pgp-keys

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to