Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FoundryBlazor/~/css/open-iconic Potentially comprosed repo's. bad redirect #104

Open
ketchup57 opened this issue Jan 8, 2025 · 0 comments

Comments

@ketchup57
Copy link

ketchup57 commented Jan 8, 2025

Just an FYI, I came across this researching your project FoundryBlazor, Blazer3js. This open Source Project:
https://github.com/iconic/open-iconic
appears to have code referenced url's that redirect to a bad url. It's currently redirected to namecheap.com. (maybe a future project their selling) But Overall depending on what environments this may be deployed in, I'd give your own assetment... (Noticed SAIC from ndc video)

You have this projected referenced here.
https://github.com/ApprenticeFoundry/FoundryBlazor/tree/develop/wwwroot/css/open-iconic
-permalink-
https://github.com/ApprenticeFoundry/FoundryBlazor/blob/3f50ca0fc618fd612b88d990b0c9943ea69e4b41/wwwroot/css/open-iconic/README.md
https://www.virustotal.com/gui/domain/appstudio.dev/relations
https://www.reversinglabs.com/blog/iconburst-npm-software-supply-chain-attack-grabs-data-from-apps-websites
https://github.com/ionic-team/ionicons (public url and redirects to this github from article above.)
Theres a lot of confusion between what would/could be a safe source for some icons...

I'm going to assume this project and any others from this github might be "HighJacked" or designed to be a network of repos for Malicous Activity. I dont know the code, just doing a research project...

OpenIconic's Github page doesn't seem to be updated. There is a history of this url and project having possibly malicious activity and history of problems here. ( These two DNS registrar's GoDaddy and Namecheap, have higher registered Malicious Activity with known nation state hacking groups, referencing from previous job experience)

Just following URL's and IP's tracked to DNS records circles around known malicious activity. Follow the different links across virus total. This specific github may not have know effected code, but I would add some tally's to risk panel on the community and projects tied to this github. https://github.com/iconic Follow your gut.

I have some extra notes I can share if needed. I'll be raising issues and referencing these posts.
iconic/open-iconic#60
mdo/ama#319

Would you mind if I reached out (email from profile?) for some questions about FoundryBlazor?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant