[manjaro-dev] Operation Windigo

jakobdee at openmailbox.org jakobdee at openmailbox.org
Mon Feb 1 13:18:46 CET 2016


Hi ...with regards,i was concerned though unsure whether it warranted 
alarm.

Heres my previous message.

But,i have a query that i dont want to air on forum ... for fear of 
causing mass hysteria (which usually happens  :o) ... and i couldnt find 
a dedicated security individual within the listed Manjaro team ... ive 
been doing a security audit ... and chkrootkit unearthed a possible 
Linux/Ebury ... further investigation showed 
https://securityaffairs.co/wordpress/23178/cyber-crime/linux-operation-windigo-eset.html 
running the command yeilded an 'infected system' ... however im not 
running a server,other than sqlite .. is it a false positive? ... 
reinstalling ssh components? just didnt particularly want to reinstall 
my system ... if a manual extraction could be done.
Whos the best person in Manjaro to discuss these matters in future?


Hi,

please post this issue best at manjaro-security at manjaro.org, and 
probably manjaro-dev at manjaro.org too.
Entire team will be informed this way, and I believe Jonathon is the 
security guy in general.


More information about the manjaro-dev mailing list