logoalt Hacker News

fwlrtoday at 7:55 PM1 replyview on HN

From the article: “[for Windows victims,] the [malicious] build script [fetches the attacker’s remote payload,] writes [it] to %TEMP%\rust-setup.ps1 and starts [it] through a VBScript launcher under wscript.exe, with a comment in the source explaining why:”

And the comment is:

    // ShellExecute via WScript escapes Cargo's job object; spawned children otherwise
    // keep the build script (and `cargo build`) waiting until they exit.
So the malicious build script has a helpful comment (???), written in a familiar “terse nouns verbing” style (!!!).

Would it be gauche to speculate? Maybe some script kiddy sweet-talked Fable into dropping its safeguards, or maybe Anthropic is doing a training run for Fable 5.1 and the air-gaps aren’t gapping.


Replies

nottorptoday at 8:30 PM

Eh, just because the likes of Anthropic are only threatening you with their latest model, it doesn't mean older models can't do exploits...