News

Sourceforge Hijacks GIMP and Nmap with Trojans

Sourceforge has been found to be hijacking orphaned open source projects and adding malware to their repositories. Notable victims of this practice are the popular GIMP and Nmap accounts, using them to distribute third-party “bundle-ware” installers. GIMP fell victim to this scheme last week, and now Nmap has been “adopted” by Sourceforge, as Gordon “Fyodor” Lyon, creator of Nmap, reports:

Hi Folks!  You may have already read the recent news about Sourceforge.net hijacking the GIMP project account to distribute adware/malware. Previously GIMP used this Sourceforge account to distribute their Windows installer, but they quit after Sourceforge started tricking users with fake download buttons which lead to malware rather than GIMP.  Then Sourceforge took over GIMP’s account and began distributing a trojan installer which tries to trick users into installing various malware and adware before actually installing GIMP.  Of course this goes directly against Sourceforge’s promise less than two years ago:

“we want to reassure you that we will NEVER bundle offers with any project without the developers consent”

http://sourceforge.net/blog/advertising-bundling-community-and-criticism/

So much for that promise!  Anyway, the bad news is that Sourceforge has also hijacked the Nmap account from me.  The old Nmap project page is now blank:

http://sourceforge.net/projects/nmap/

Fyodor asks Sourceforge to remove the hijacked Nmap page, and reminds users to only download Nmap from the official SSL Nmap website.

Sourceforge later responded to the controversy, issuing the following statement:

“In an effort to address a number of concerns we have been hearing from the media and community at large, we at SourceForge would like to note that we have stopped presenting third party offers for unmaintained SourceForge projects.”

Thank you Ars Technica and Seclists.org for providing us with this information.

Image courtesy of CyberKendra.

Ashley Allen

Disqus Comments Loading...

Recent Posts

Plaion Launches Retro ZX Spectrum Computer

Plaion, a leading video game publisher, and Retro Games Ltd., a specialist in reimagined classic…

2 days ago

NVIDIA Warns of GeForce RTX 40 Graphics Card Shortages in November and December

During the latest earnings call, NVIDIA CFO Colette Kress warned of a potential GPU supply…

2 days ago

GeForce RTX 5090, RTX 5080, RTX 5070 Ti, and RTX 5070 Reportedly Coming in Q1 2025

Chinese sources say the GeForce RTX 5090, RTX 5080, RTX 5070 Ti, and RTX 5070…

2 days ago

GTA 6 Already Winning Awards Before Its Launch

GTA 6 doesn’t have an official release date yet, but it has already earned a…

2 days ago

DJI Osmo Mobile 6, 3-Axis Phone Gimbal

Stay on Point with ActiveTrack 6.0 - With upgraded tracking tech, OM 6 sticks to…

2 days ago

Drayton Wiser Smart Radiator Thermostat TRV

Pack includes three Wiser Radiator Thermostats. These smart radiator thermostats are only designed to work…

2 days ago