Open Source · · 1 day
Gentoo GitHub hack modified ebuilds
An attacker gained control of a Gentoo GitHub organization administrator account, using a password Gentoo later described as guessable from one the admin had used elsewhere.
Gentoo's 2018 incident hit GitHub, not Gentoo's primary infrastructure. The attacker gained access to a GitHub organization administrator account and used that control to remove users, invite another malicious administrator, and alter repositories.
The visible payload was destructive. Malicious commits added rm -rf commands to ebuild-related content and defaced repository files. Gentoo later noted that technical guards made execution by ordinary users unlikely, but fresh clones from the affected GitHub repositories during the window could contain hostile content.
The main Gentoo development and distribution infrastructure remained separate. Gentoo told users that the default mirroring infrastructure and hardware run by Gentoo Infrastructure were unaffected, and that users could verify repository provenance through Portage verification.
The operational damage was still real. GitHub use was unavailable for several days, pull-request workflows were disrupted, and old pull requests were disconnected from their commits. This record tracks the compromised GitHub source mirror and ebuild changes, not a compromise of Gentoo's canonical package distribution path.
Notes
- Gentoo's incident report listed malicious content windows for gentoo/gentoo, gentoo/musl, and gentoo/systemd on GitHub between 2018-06-28 and 2018-06-29 UTC.
- Gentoo stated its own infrastructure and default mirroring path were unaffected.
Appendix · Affected releases
- Gentoo restored the branch to legitimate commit 73b724093b9c2a8756b8c35d3e09793342fa9ca9.
- afcdc03b added the destructive line to every ebuild; e6db0eb4 was a root-commit squash of that malicious tree.
- The attacker force-pushed the same malicious Gentoo tree to gentoo/musl.
- Gentoo restored the branch to legitimate commit 60461ca1385809bacf6a114a7f1ecfe22f6da47f.
- c46d8bbf retained the malicious configure change while squashing another revision.
- Gentoo restored the branch to legitimate commit bf0e0a4df2d41a5631811f7db6b6c1c866c3ed80.
Indicators
- file_sha256skel.ebuild a847becd7d479d741acb9b27fe07afffee49bafe2299ab4c8d9fa65b4abaf2e1
- file_sha256SphinxTrain-1.0.8.ebuild 29af3458b53e939dc2a51c3633bdf8854a78f34cb3eeaf5876c7660f6e0e6be4
- file_sha256configure cd0ba251f05ab646850c231bf0354ba984bd9841c0a47ce92456b81a469568d1
References
- Gentoo Linux GitHub organization hacked and defacedarstechnica.com
- Github Gentoo organization hacked - resolvedgentoo.org
- Gentoo GitHub 2018-06-28 incident reportwiki.gentoo.org
Source record: oss/attacks/gentoo/meta.yaml