news
User Flags Possible Malware Incident on Xubuntu.org
Quoting: User Flags Possible Malware Incident on Xubuntu.org —
This isn’t the kind of news I enjoy sharing, but unfortunately, it’s part of the story we have to tell. Here’s what’s going on. A Reddit user has raised a serious security concern, claiming that the official Xubuntu website may have been compromised and was briefly serving malware through its download page.
According to the post, clicking the site’s “Download” button reportedly led to a file named “Xubuntu-Safe-Download.zip”, which contained a Windows executable identified by VirusTotal as a Trojan. The malicious file appeared to masquerade as an installer and included a fake terms-of-service document to look legitimate.
Also:
-
Xubuntu Website Compromised, Served Malware Downloads - OMG! Ubuntu
Users who visited the Xubuntu website over the weekend to download the official .torrent of the Xfce-toting Ubuntu flavour instead got a xubuntu-safe-download.zip.
When the rogue zip file was extracted it contained an .exe runtime and a ‘terms of service’ text file.