← Back to context

Comment by monster_truck

3 days ago

They're generally extremely quick about this if you ping ~anyone on the security team with the offending url and a link to the real repo. There is a long ongoing game of cat & mouse against malware in repackaged things like first party windows utilities to leverage the signed binaries.

>if you ping ~anyone on the security team

And how I am supposed to know who they are or how to reach them?