@yuki_the_maven Sorry I wasn't clear, I meant actually downloading composer
`hash_file('SHA384', 'composer-setup.php') == [hash]`
Is part of the download instructions. I was wondering if you knew if that is one of these methods or maybe another method of checking a binary. Thanks for the knowledge though, this stuff is super interesting.
tech gitea Show more
@stephen from reading the thread I seem to understand that the attack was widespread to multiple accounts with same mo but not particularly stealth at all, replacing the exe binary entirely. are there other elements that suggest the attack is sophisticated? (like, I actually didn't get how the acct was taken over from the info on the thread tbh)