top | item 42767526

(no title)

beginning_end | 1 year ago

Any advice on what to do if you might be a victim to this?

discuss

order

addandsubtract|1 year ago

Apparently, it was collecting passwords from victim machines. So, step one would be to remove everything the script put onto your machine. Step two would be to change your passwords.

chatmasta|1 year ago

Step one is to unplug the machine from the internet. Step two is to use another machine to change all your passwords, starting with the “pivot” passwords - your password manager master password, your email accounts, your AppleID, your mobile provider - followed by financial accounts and then all others. While changing passwords, make sure to “invalidate all sessions” where possible.

Only after you’ve done all this should you move onto Step 3: reformat your computer and install the OS from scratch.

watermelon0|1 year ago

Step 3 should probably be reinstalling the OS, and restoring data from backup (ideally from before the malicious version was installed).

hollin|1 year ago

Is there any way to check if you're affected? I just happened to install Homebrew while the malicious site was up and now I'm not sure if I installed the legit version.

npteljes|1 year ago

I'd isolate the machine from the internet, change my passwords from a trusted machine, save the media and documents from the isolated machine, and then reinstall the OS / factory reset the isolated machine. Still, I'm sure that there are technical possibilities that this doesn't account for, but I think I would be okay with the procedure nevertheless.