News

Published on May 3rd, 2019 📆 | 7128 Views ⚑

0

Mystery Git ransomware appears to blank commits, demands Bitcoin to rescue code • DigitalMunition


iSpeech

Programmers say they've been hit by ransomware that seemingly wipes their Git repositories' commits and replaces them with a ransom note demanding Bitcoin.

An unusual high number of developers have griped online about the effects of the software nasty, with at least two reports seen by El Reg referencing the freeware Sourcetree GUI for Git, made by Atlassian.

"So I was done fixing a bug tonight. I was using sourcetree to push the changes, as soon as I clicked the commit button my laptop freezed (it usually freezes so im not sure if it was due to malware or the usual one) and i immediately restarted it by long pressing the power button," posted one person on Reddit.

The netizen added that the ransom note they received referenced gitsbackup[dot]com, and demanded about $560 in crypto-currency to un-fsck the repo.

Another posted on Stack Exchange: "One of my repos was wiped today and just a message left in its place with a bitcoin ransom. I've no idea how they accessed my account, can't really see anything on github security page."

The user added: "I'm at a bit of a loss just now as what to do, 2 factor has been turned on in github, the main server where the code was used. I've removed unused scripts etc changed passwords, currently building a new server droplet and moving everything as a precaution in case the server was accessed."

A third, Stefan Gabos, wrote on Stackexchange: "I was working on a project and suddenly all the commits disappeared and were replaced with a single text file."

That file, consistently across all the posts seen by DigitalMunition, reads:





To recover your lost code and avoid leaking it: Send us 0.1 Bitcoin (BTC) to our Bitcoin address 1ES14c7qLb5CYhLMUekctxLgc1FV2Ti9DA and contact us by Email at admin[at]gitsbackup[dot]com with your Git login and a Proof of Payment. If you are unsure if we have your data, contact us and we will send you a proof. Your code is downloaded and backed up on our servers. If we dont receive your payment in the next 10 Days, we will make your code public or use them otherwise.

Gabos added that he was "using SourceTree but somehow I doubt that SourceTree is the issue, or that my system (Windows 10) was compromised. I'm not saying it's not that, it's just that I doubt it." He told El Reg he is running the most recent version of Sourcetree (3.1.3), having updated today from the previous version. The changelog is here.

Gabos added on Stackexchange that his code does not appear to have gone altogether as accessing his commit's hash had worked, concluding: "So the code is there but there's something wrong with the HEAD." He continued to note that git reflog "shows all my commits", updating as he learned more in his quest to recover his commits. In an edit, he added:

Atlassian, maintainer of Sourcetree, had not responded to DigitalMunition's inquiries at the time of publication. ®

Sponsored:
Cloud Security: From Start Point to End Point

Source link

Tagged with:



Comments are closed.