The Gentoo distribution has replaced its GitHub mirror after it was reportedly taken over by someone who compromised the code repository.
In a warning, the Gentoo project announced that an attacker had gained control of the Gentoo Github on June 28 at 11:20 GMT.
“All Gentoo code hosted on github should be considered compromised for now,” the notice said.
The Gentoo project said its infrastructure is considered secure and that users should be fine if they rsync or webrsync from gentoo.org.
A post on the gentoo-dev mailing lists says that the attacker replaced all portage and musl-dev trees with ebuilds that would attempt to remove all files from the end user’s system.
Although the malicious code should not work as is and GitHub has now been restored, please do not use any ebuilds from the GitHub mirror obtained before 28/06/2018, 9:00 (Greece time) until further notice.
The distribution has not provided further details on how the attack was carried out.
__________________________________
