ghrc.io Appears to be Malicious

63 points by iris


janus

Microsoft:

Let’s buy the microsoft tld, scammers won’t have the millions of dollars necessary to set up a typo squat TLD!

Also Microsoft:

Person 1: Which TLD should we use for our container registry?

Person 2: What about the using the TLD of the Chagos Islands in the Indian Ocean?

mrexodia

There are 972 results on GitHub for ghrc.io (I typod this). Mostly typos in documentation, but likely some repositories are really affected: https://github.com/search?type=code&q=ghrc.io

Riolku

Is it reasonable to expect one of:

Or are these unpalatable mitigations?

fiatjaf

I’m reading this and the comments and having a hard time to figure out which one is the malicious and which one is the original.