Summary
Starting on Sep 7th, 2024 at 00:00 UTC our AllSky installation (version v2023.05.01_03) stopped working. Checking it out, we have found a strange config.sh
file with some Base64 content, decoding it appears to be a script to download and execute software from a remote server.
Details
The malicious content has appeared in config.sh
, with a suspicious header:
### IMPORTANT ALLSKY LINE, DO NOT REMOVE!
PoC
Content of ~/allsky/config/config.sh
:
Decoded content:
Impact
We do not know the effect of the execution of the remote software.
Summary
Starting on Sep 7th, 2024 at 00:00 UTC our AllSky installation (version v2023.05.01_03) stopped working. Checking it out, we have found a strange
config.sh
file with some Base64 content, decoding it appears to be a script to download and execute software from a remote server.Details
The malicious content has appeared in
config.sh
, with a suspicious header:PoC
Content of
~/allsky/config/config.sh
:Decoded content:
Impact
We do not know the effect of the execution of the remote software.